Skip to main content
kcanalichio
New Member
May 28, 2021
Question

Alerts for 0 events

  • May 28, 2021
  • 1 reply
  • 665 views
Does anyone know how to create an alert in fortiseim that will alert if no events the match the filter in a 24 hours period.

I have tried matched events = 0  and matched events = NULL, but neither seem to work

    1 reply

    KarnGriffen
    Explorer II
    June 1, 2021
    There is no great way to do this.  I've attached a rule we use now that looks for a SUM(Event Rate) that is below a threshold.-------------------------------------------
    Original Message:
    Sent: May 28, 2021 07:51 AM
    From: Kevin Canalichio
    Subject: Alerts for 0 events

    Does anyone know how to create an alert in fortiseim that will alert if no events the match the filter in a 24 hours period.

    I have tried matched events = 0  and matched events = NULL, but neither seem to work