After many test, my saved search is still in mode "Report" with only "alert.track=1". An alert type seems to be consisted of 3 points: A cron schedule A trigger condition A trigger actions In my case, here is the options used with the endpoint API "POST /servicesNS/-/-/saved/searches" to get an alert type: "is_scheduled": 1, "alert_type": "number of events" "alert_comparator": "greater than", "alert_threshold": 0, "alert.track": 1 If I remove one of these options, I get a report saved search instead of alert. With the configuration file (savedsearches.conf), the options are "cron_schedule, enableSched, counttype, relation, alert.track".
... View more