-I am running an alert which is not triggering email actions when using real-time option. The alert is used to search for hosts which have not sent logs in the last 5 minutes.
-For example, I shut down a host for testing and wait 5 minutes. I then manually use the search string and specify time frame (e.g. last 15 minutes)- I am able to obtain results.
However, even though the same search was configured in the form of an alert running in real time, it produces no results nor does it trigger an email.
Here is the search I am using:
index=* | stats max(_time) as latest by host | eval recent= if(latest > relative_time(now(),"-5m"),1,0). realLatest = strftime(latest, "%Y-%M-%D %H%M%S") | fields - latest | where recent = 0 | rename host AS Host, realLatest AS "Latest Timestamp" | table Host, "Latest Timestamp"
... View more