Page 1 of 1
possible to negate the alert?
Posted: Sat Feb 11, 2017 8:14 am
by nozlaf
Alerts only seem to be possible if the query returns a hit, i want to alert if a query does not return a hit
e.g. I want to query for a username in a log, if the user does not login for 20 days I want to send an alert.
is this possible?
Re: possible to negate the alert?
Posted: Mon Feb 13, 2017 10:30 am
by rkennedy
Sure is! Set the lookback / check interval to 20d with the thresholds at 1: for warning and critical.
Re: possible to negate the alert?
Posted: Tue Feb 14, 2017 6:20 am
by nozlaf
thanks ill give it a try
Re: possible to negate the alert?
Posted: Tue Feb 14, 2017 6:23 am
by nozlaf
would help if i had just hovered over the ? right
Re: possible to negate the alert?
Posted: Tue Feb 14, 2017 10:23 am
by mcapra
Perhaps

Though there are significant efforts being made to have the GUI explain topics such as that more effectively.