I have some trouble wrapping my head around edge cases for alerts and I’m hoping someone can enlighten me.
Use case 1: An alert for every message matching the alert condition is desired, no matter how many. Example: SSH login from a special account (say "root). Howto do this?
Use case 2: An alert for only the first message matching the alert condition is wanted IF the following matching messages are within fixed time intervals. Example: log in to an admin UI keeps refreshing and thereby repeating the login message every 15 minutes. I want to receive an alert for the first message only.
I’ve tried messing with message counts and grace periods but I can’t get it to work. Any pointers would be much appreciated!