Previous Topic: Action AlertsNext Topic: Using Queries Tagged as Action Alert


About Action Alerts

Action Alerts are specialized reports that generate an event when their query conditions are fulfilled. They can help you monitor your environment - allowing automatic notifications for a wide variety of situations and occurrences. For example, you can set action alerts to deliver event trend information, track disk space usage, or deliver notifications when failed access thresholds are exceeded.

Action alerts are a good way to sift through mountains of collected data for those few events on which you need to act right now. You can use action alerts to notify you about almost anything that happens in your log collection network. You can create alerts to let you know about spikes in inbound or outbound traffic, traffic on specific ports, access of certain privileged resources, configuration changes to various network entities like firewalls, databases, or key servers, and so forth.

You can create action alerts in the following ways:

Scheduling options are a significant part of creating an alert, so you have control over how long and how often your alert job runs.