Alerts are triggered when the results of the search meet specific conditions. For example, you might have a condition that specifies to only alert when the count of results is greater than X. Triggering conditions are set when you set up the alert, and the following table lists the various conditions that are available:
Trigger condition |
When is it triggered? |
Per-result |
Triggers whenever a search returns a result. It is only available for real-time alerts and leveraged by the per-result alert type. |
Number of results |
Triggers based on the number of search results. The options include greater than, less than, equal to, and not equal to. |
Number of hosts |
Triggers based on the number of hosts seen. ... |