How to check alerts rules

0

How can I check that my alert rules are correct and running smoothly ?

Share This Post:

2 comments

Date Votes
0
Avatar
John Couzins

I would also be interested in this as we have seen some alerts appearing to stop working and needing to be enabled and disabled to start triggering again.

We started to look at a side server to send spoofed UDP packets with alert triggering criteria, but this wouldn't work for all log sources like TCP syslog etc.

0
Avatar
Jerome Perrin

I found an “Invalid Query” button on the top-right corner of the settings menu. From there all the queries that have a problem will be highlighted.

Please sign in to leave a comment.