Hello,
We have a number of real time alerts that are working fine (that are being generated by certain Active Directory events via the Universal Forwarder installed on the DC), but when I try to create any new real time alerts they do not seem to work; I am not receiving the email, and the Alert counter on the Searches and Reports page remains on 0. When I run the search manually for the last 15 minutes, I get results that I would expect, so the search parameters seem to be ok.
I even cloned a working rule, and created an event. The original alert triggered, but the new cloned one did not 😞
... View more