I am trying to construct an alert that will only fire if we see a certain message NOT followed by a certain second message within a set period of time.
So for example: "VPN down" NOT followed by "VPN up" within 1 minute would be an alert condition.
seems to be close to what I'm looking for, but I can't figure out how to make it work when the search for Message A and Message B is something complex. e.g.,
(_sourceCategory="vec/p/pss/utm") and *Valtovpc* and 1.1.1. and "VPN down" NOT_FOLLOWED_BY_WITHIN_1_MINUTE
(_sourceCategory="vec/p/pss/utm") and *Valtovpc* and 1.1.1. and "VPN down"
Any pointers in the right direction would be appreciated!
Please sign in to leave a comment.