Hello, I created an alert, that alerts me about the service down but I need that when a service remains down from the last time I do not receive an alert for this service I only receive an alert for the new service down, how can i do it please any help !!! | inputlookup services_oracle.csv | search NOT [search index=* sourcetype=srvscript | eventstats max(_time) as TimeEvent | where _time = TimeEvent | fields CMD ] | eval statut = "DOWN" | table CMD statut
... View more