The Steps include:
- Open Search page in Search and Reporting Page.
- Enter your query for which alerts need to be triggered.for example:
index = os_web sourcetype = custom-prod-up-ext serviceName=SHARP response=failure feature=PCI_DE_TOKENIZATION
- Select Save as ---->Alert
- Next Specify Setting,Triggered Condition,Triggered Action.
Enjoy Learning.