Select tags or queries as the basis for a new action alert job. The query, plus any filters you add, defines the circumstances under which an alert is generated. For example, to create an alert to monitor traffic from a host or port, use the All Events query, add filters to define the source hosts to monitor, and an event threshold.
Note: The Action Alerts query category contains queries designed for various common alert needs.
To select an alert query
Note: Scheduling alerts by tag lets you add alerts without altering the job itself. If you select the "Identity Management" Tag, any alert with that tag is added to the job at the scheduled run time. You can add a new alert to the job by giving a query the Identity Management tag. This feature also applies to custom tags.
(Optional) Clear the Enable check box to enable to action alert later rather than as soon as you finish it. The check box is selected by default.
Note: The ability to create a disabled alert job is designed for use with recurring alerts. If you clear the Enabled check box for a job, and create that job with a single occurrence ("Now" or "Once") it is removed from the Scheduled Alert list.
If you click Save and Close the alert job is scheduled, otherwise the step you select appears.
Copyright © 2011 CA. All rights reserved. | Email CA Technologies about this topic |