Hi All, I have data like below with three fields : srcip,dstip and title . When I execute below query .........| stats count by srcip,dstip,title Result : srcip dstip title srcip1 dstip1 title srcip1 dstip2 title srcip2 dstip2 title1 srcip2 dstip3 title1 srcip1 dstip2 title2 So we required to alert separate on basis title values. For all events of one title, there should be one alert. So above example there should be trigger 3 separate alerts . Thank you ! in Advance
... View more