Alert rules automatically run log searches at regular intervals that you define in the rule. If the log search returns results that match the defined criteria, then an alert record is created and an action can be performed, based on what you define in the alert rule.
The following properties are required in an alert rule:
- Search query: The query upon which an alert rule is based will run every time the alert rule executes.
- Time window: The time range of current time for which records are returned by the search query. This time window can range between 5 minutes and 24 hours. For instance, if you set the range to the default 15 minutes and the query is run at 12:00 PM, the search query will return only records created between ...