Dear all =)
I would like to create an alert that triggers a webhook each time host:10.10.10.10
is found in the log stream example_test
.
When I click on " Stack Management" and then "Create Alert" I get presented with the options
- Index Threshold
- Inventory
- Log threshold
- Metric threshold
- Uptime monitor status
- Uptime TLS
and each looks like SQL statements and not KQL.
Question
Can anyone tell me how I can have a KQL statement evaluated each minute, and if it finds a hit, then trigger a webhook?
Hugs,
Sandra =)