<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Custom alerts for log monitoring in Alerting</title>
    <link>https://community.dynatrace.com/t5/Alerting/Custom-alerts-for-log-monitoring/m-p/208785#M3441</link>
    <description>&lt;P&gt;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/18264"&gt;@dannemca&lt;/a&gt;&amp;nbsp;- the timeshift only moves the time, it is used as a timeframe window. So -1d will not give the last 24 hours, but just make the current date and time, 1 day before.. I.E 31st March becomes 30th March&lt;/P&gt;</description>
    <pubDate>Fri, 31 Mar 2023 12:52:06 GMT</pubDate>
    <dc:creator>Tom_Eaton</dc:creator>
    <dc:date>2023-03-31T12:52:06Z</dc:date>
    <item>
      <title>Custom alerts for log monitoring</title>
      <link>https://community.dynatrace.com/t5/Alerting/Custom-alerts-for-log-monitoring/m-p/199159#M3240</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;I would like to create a custom alert on log monitoring whereby an alert is raised when more than 1 log events occurred in a day. I tried to configure the custom event to raise an error when the metric threshold is above 1 in the given day, which is 1440 minutes. However, the maximum value of minutes period is 60. Can anyone advise me on this issue?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jc___0-1669347452192.png" style="width: 815px;"&gt;&lt;img src="https://community.dynatrace.com/t5/image/serverpage/image-id/8640i41CB3C4105FCA70B/image-dimensions/815x379?v=v2" width="815" height="379" role="button" title="jc___0-1669347452192.png" alt="jc___0-1669347452192.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Nov 2022 07:58:10 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Alerting/Custom-alerts-for-log-monitoring/m-p/199159#M3240</guid>
      <dc:creator>jc__</dc:creator>
      <dc:date>2022-11-25T07:58:10Z</dc:date>
    </item>
    <item>
      <title>Re: Custom alerts for log monitoring</title>
      <link>https://community.dynatrace.com/t5/Alerting/Custom-alerts-for-log-monitoring/m-p/199197#M3241</link>
      <description>&lt;P&gt;Correct me if I am wrong, but if you get an alert in 1h, it means that you got an alert that day, and you will need to be notified about it.&lt;/P&gt;&lt;P&gt;The only problem with the 1h instead 24h is that you may end up receiving more than one alert per day, which may indicates that the system you are monitoring is not so healthy and the attention is required.&lt;/P&gt;&lt;P&gt;You can also work with metrics transformation, for example, limiting the data points to the last day with :timeshift(-1d) and then combine the data to a single point with :fold.&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;your.custom.metric.for.log:timeshift(-1d):fold&lt;/P&gt;&lt;P&gt;Try and let us know.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Nov 2022 13:19:01 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Alerting/Custom-alerts-for-log-monitoring/m-p/199197#M3241</guid>
      <dc:creator>dannemca</dc:creator>
      <dc:date>2022-11-25T13:19:01Z</dc:date>
    </item>
    <item>
      <title>Re: Custom alerts for log monitoring</title>
      <link>https://community.dynatrace.com/t5/Alerting/Custom-alerts-for-log-monitoring/m-p/199346#M3243</link>
      <description>&lt;P&gt;Hi dannemca ,&lt;/P&gt;&lt;P&gt;Thank you for responding.&lt;/P&gt;&lt;P&gt;I might not have make myself clear in the question asked.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The requirement:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Raise an alert if the metric is above the static threshold of 1 in 2 one minute slot during a day (24 hrs)&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The scenario:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Our client has a server that will restart once everyday, hence, one "initialized" keyword will be observed in the log. If there is more than 1 "initialized" keyword raised in a day, an alert should be raised so that our client can look into the issue.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;May I know if there is any way to achieve the above requirement?&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 08:54:09 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Alerting/Custom-alerts-for-log-monitoring/m-p/199346#M3243</guid>
      <dc:creator>jc__</dc:creator>
      <dc:date>2022-11-29T08:54:09Z</dc:date>
    </item>
    <item>
      <title>Re: Custom alerts for log monitoring</title>
      <link>https://community.dynatrace.com/t5/Alerting/Custom-alerts-for-log-monitoring/m-p/201024#M3279</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/18264"&gt;@dannemca&lt;/a&gt;! Do you know if that alerting requirement that jc_ mentioned above is actually possible to achieve? Thank you for your help in advance!&lt;/P&gt;</description>
      <pubDate>Thu, 22 Dec 2022 16:13:45 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Alerting/Custom-alerts-for-log-monitoring/m-p/201024#M3279</guid>
      <dc:creator>Michal_Gebacki</dc:creator>
      <dc:date>2022-12-22T16:13:45Z</dc:date>
    </item>
    <item>
      <title>Re: Custom alerts for log monitoring</title>
      <link>https://community.dynatrace.com/t5/Alerting/Custom-alerts-for-log-monitoring/m-p/208783#M3440</link>
      <description>&lt;P&gt;You could look into a possible similar solution as I have seen once before:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Create a log metric to find the log messages with '&lt;EM&gt;initialized' - use matchesPhrase&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;Then create an SLO using a metric selector with the defualt(0,always) for your log metric - this will give every 1 minute sample a 0 default value when data is missing.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I have seen this used for a similar scenario for a batch job with a log being written once a day, looking for a day when it was not written - so someone used a SLO to look back -25 hours&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;This might be a possible avenue to explore.&amp;nbsp;&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Fri, 31 Mar 2023 12:50:04 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Alerting/Custom-alerts-for-log-monitoring/m-p/208783#M3440</guid>
      <dc:creator>Tom_Eaton</dc:creator>
      <dc:date>2023-03-31T12:50:04Z</dc:date>
    </item>
    <item>
      <title>Re: Custom alerts for log monitoring</title>
      <link>https://community.dynatrace.com/t5/Alerting/Custom-alerts-for-log-monitoring/m-p/208785#M3441</link>
      <description>&lt;P&gt;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/18264"&gt;@dannemca&lt;/a&gt;&amp;nbsp;- the timeshift only moves the time, it is used as a timeframe window. So -1d will not give the last 24 hours, but just make the current date and time, 1 day before.. I.E 31st March becomes 30th March&lt;/P&gt;</description>
      <pubDate>Fri, 31 Mar 2023 12:52:06 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Alerting/Custom-alerts-for-log-monitoring/m-p/208785#M3441</guid>
      <dc:creator>Tom_Eaton</dc:creator>
      <dc:date>2023-03-31T12:52:06Z</dc:date>
    </item>
  </channel>
</rss>

