[SOLVED] Filter messages with "Event Severity: Critical" in Event Definition

I would like to set an Event Condition as “Event Severity: Critical” but when I’m in the “Filter & Aggregation” tab and type that condition in the “Search Query” box there are no messages. (1)

Although if I search “event_severity: critical” in the main page (Search) and filter in the last 30 days actually there are messages. (2)

Alerts → Event Definitions → Edit → Filter & Aggregation → type “event_security: critical” in the Search Query input box

  • Windows

It seams that the two screenshots are the same.
What I understand about your issue is that the field event_severity is populated, have you tried increasing “Search within the last” time frame?

also, are you using the right stream for the Filter & Aggregation?

Thank you, now it works :slight_smile:

