Hi,
One of my customers enabled a real-time search and alerting that has started sending out thousands of messages. Some of these alerts are based upon data that is over a year old. The logs that provide this data were recently added, but I don't understand why old data would get triggered from a real-time search.
Because realtime searches search over all incoming data as it comes in in real time, regardless of the events' timestamps.
Thanks. Is there a way to have a "continuous" search running that only looks at recent events?