Administration Guide › Action Alerts › Example: Create an Alert for Business_Critical_Sources
Example: Create an Alert for Business_Critical_Sources
You can create a custom query with the Business_Critical_Sources keyed list and schedule an alert based on this query. The keyed list is one that has no default values and no associated predefined query or alert. Use the following end-to-end process as a guide.
- Install an agent.
- Configure a connector on that agent to collect events from each business critical source.
- Define the hostname values for Business_Critical_Sources user-defined lists (keys).
- Click the Administration tab and Services subtab.
- Select Report Server from the Service List.
- Select Business_Critical_Sources in the User Defined Lists (Keys) area.
- Click Add Value in the Values area and enter the hostname of a business critical source.
- Repeat the last step for each business critical source from which events are collected.
- Click Save.
- Create a query on failed login attempts on business critical sources.
- Click Queries and Reports.
- Under Query List, enter login in the Search field.
- Select Unsuccessful Login Attempt by Host and select Copy from the Options drop-down list.
The Query Design wizard opens with the name Copy of Unsuccessful Login Attempts by Host.
Rename to query to Unsuccessful Login Attempts by Business_Critical_Sources.
- Select the Query Filters step.
- Click the Advanced Filters tab.
- Click New Event Filter.
- Select source_hostname for the column, select Keyed for the operator, and select Business_Critical_Sources as the value.
- Click Save and Close.
- Schedule an alert based on this custom query.
- Click the Queries and Reports tab.
- Select Unsuccessful Login Attempts by Business_Critical_Sources under the User folder of the Query List.
- Select Schedule Action Alert from the Edit drop-down list.
The Schedule Action Alerts wizard appears.
- Enter a job name, such as Unsuccessful Login Attempts by Business Critical Resources
- Click Schedule Jobs and define the schedule.
- Optionally, specify email options for Destination.
- Click Save and Close.
- Verify the job is scheduled.
- Click the Alert Management tab and the Alert Scheduling subtab.
- Verify the job name you entered is listed.
- Check for the generation of the alert.
- Click the Alert Management tab. The Action Alerts subtab is displayed.
- View the listed alerts to determine whether the job name you listed appears.
More information:
Install an Agent
Create a Connector Based on NTEventLog