There's more...

When the criteria defined in an alert rule is matched by the results of the search query, then an alert record is created. These records are stored as events in the Alert table in the OMS repository and are of type alert. Alert records created by alert rules in Log Analytics have a SourceSystem property value of OMS. This can be used to distinguish them from alert records from other sources, such as SCOM and the Alert Management solution.

You can use this query to find alert records in your workspace:

Alert| summarize count () by SourceSystem

This query aggregates the content of the Alert table and returns the count of alert records by the SourceSystem property:

Figure 3.6

You can view the properties of an alert record generated ...

Get Microsoft Operations Management Suite Cookbook now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.