[SOLVED] Filter messages with "Event Severity: Critical" in Event Definition

Description of your problem

I would like to set an Event Condition as “Event Severity: Critical” but when I’m in the “Filter & Aggregation” tab and type that condition in the “Search Query” box there are no messages. (1)
1

Although if I search “event_severity: critical” in the main page (Search) and filter in the last 30 days actually there are messages. (2)
2

Description of steps you’ve taken to attempt to solve the issue

Alerts → Event Definitions → Edit → Filter & Aggregation → type “event_security: critical” in the Search Query input box

Environmental information

Operating system information

  • Windows

Hello && Welcome

It seams that the two screenshots are the same.
What I understand about your issue is that the field event_severity is populated, have you tried increasing “Search within the last” time frame?

also, are you using the right stream for the Filter & Aggregation?

1 Like

Thank you, now it works :slight_smile:

1 Like

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.