Usually I find an individual alert, i.e., a saved search, among a large number of alerts by searching for it by name. How can I find the individual alert that generates a known, specific alarm-ID, e.g. "file error 12345"? More generally, how does one find an alert, among a large number of alerts, based on the contents of the events it generates? Is there a way to find all alerts that generate alarm IDs containing a text, i.e. where the text is a substring of the complete alarm IDs. For example, all alerts that generate alarm IDs containing "file error"?
... View more