I'm making a query that should fire if the number of events goes down by 1 or more.
The setting on E-mail Alert is "if number of events drops by".
Is that drops by X exactly, or drops by at least X?
The Answers answer to this Answers post is: "Basic conditional alerts trigger alert actions when set thresholds in the number of events, sources, or hosts in your results are exceeded.
i.e. "at least X"
The Answers answer to this Answers post is: "Basic conditional alerts trigger alert actions when set thresholds in the number of events, sources, or hosts in your results are exceeded.
i.e. "at least X"