05 Feb 2026
08:55 PM
- last edited on
10 Mar 2026
02:17 PM
by
GosiaMurawska
Hi Folks,
I have a Davis Anomaly Detection rule configured on SNMP logs, with a workflow in place to forward notifications.
Issue:
Observed timeline example:
Is there a way to reduce the end-to-end delay to 1–2 minutes?
Regards,
AK
Solved! Go to Solution.
06 Feb 2026 02:38 AM
@AK The delay looks to be during event analysis , are you using the log events or Davis anomaly detection app rule?
06 Feb 2026 10:13 AM
@p_devulapalliI'm pulling logs and creating a time series to trigger alerts—here's the example query I'm using in Davis Anomaly Detection.
fetch logs
| filter matchesValue (log.source, "trap") and matchesValue (trapoid, "Critical")
| makeTimeseries count(), by:{Device, Message, device.address, dt.source_entity,trapoid},interval:1m
09 Feb 2026 02:09 AM
@AK Do you have any of the below set to longer duration which can impact the time the problem is generated
18 Feb 2026 06:44 AM
@p_devulapalli Thanks for looking into this. I had been using Davis Anomaly Detection, but after switching to the Davis included in the open pipeline, the delay dropped dramatically to about one to two minutes. Attached is a screenshot of the configuration.
Thanks again for your helpful insights and assistance.
Regards,
AK
Featured Posts