We have a rule that seems to have modified itself somehow.
Previously the filter for the rule was "healthcheckname : name and not healthstatus : Healthy"
However, around midnight last night the filter got modified to: "healthcheckname : Warning and not healthstatus : Warning"
All of this is very weird because I am the only person with the rights to change rules, and I don't sleepwalk or take ambien
Any ideas what could have happened?
UPDATE:
It happened again. Last night, 15 alerts mysteriously changed to use Data View: * instead of the correct index.
I see absolutely no logs indicating that they were edited. We just suddenly started getting spammed with alert emails.