Perhaps you could create an alert which would search for those three alerts in
index="_audit" action="alert_fired"
Perhaps you could create an alert which would search for those three alerts in
index="_audit" action="alert_fired"
index=_audit action="alert_fired" ss_name=Alert1 OR ss_name=Alert2 OR ss_name=Alert3 | stats dc(ss_name) as alerts
and you should fire the alert if alerts = 3
Thanks for the update but how can I search multiple alert names as an 'AND' condition.
Ex: Alert1 and Alert2 and Alert3 all have fired.