8 years ago

Logging based on number of alerts in a given window

We have regular event log entries which on their own are not substantial, however in bulk they become a problem. 

It would be beneficial to have a mechanism whereby I can say tell Logicmonitor to alert me differently if it detects a certain number of a specific alert in a time window. 

I.e. trigger escalation chain '500Errors' when we see <100 errors of event ID "2070" in last 1h.