Page 1 of 1

possible to negate the alert?

Posted: Sat Feb 11, 2017 8:14 am
by nozlaf
Alerts only seem to be possible if the query returns a hit, i want to alert if a query does not return a hit


e.g. I want to query for a username in a log, if the user does not login for 20 days I want to send an alert.

is this possible?

Re: possible to negate the alert?

Posted: Mon Feb 13, 2017 10:30 am
by rkennedy
Sure is! Set the lookback / check interval to 20d with the thresholds at 1: for warning and critical.

Re: possible to negate the alert?

Posted: Tue Feb 14, 2017 6:20 am
by nozlaf
thanks ill give it a try

Re: possible to negate the alert?

Posted: Tue Feb 14, 2017 6:23 am
by nozlaf
would help if i had just hovered over the ? right

Re: possible to negate the alert?

Posted: Tue Feb 14, 2017 10:23 am
by mcapra
Perhaps :P Though there are significant efforts being made to have the GUI explain topics such as that more effectively.