There's more...

Alert records created by alert rules in Log Analytics have a SourceSystem property value of OMS. This can be used to distinguish them from alert records from other sources, such as SCOM, and from alerts from Nagios and Zabbix.

You can use this query to find alert records in your workspace:

Alert| summarize count () by SourceSystem

This query aggregates the content of the Alert table and returns the count of alert records by the SourceSystem field property:

Figure 3.38

You can also use the SourceSystem field to specify alerts generated from a certain connected source. For instance, this query finds alert records for alerts generated ...

Get Microsoft Operations Management Suite Cookbook now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.