Correlation Alert SLA Status

The correlation alert SLA status query displays the status of correlation alerts.

Query

use LogLogic_AdvancedAlerts_SLA

Description

This query displays the status of alerts that are currently triggered in the system.

Query result

The following fields are returned in the search results:

Field Data type Description
lls_alertTime TIMESTAMP Date and time when the alert is created
lls_slaExpiration DURATION Time to expiration, displayed as Duration data type
lls_ruleName STRING Rule name
lls_state STRING Alert state
lls_ackTime TIMESTAMP Time when the alert is acknowledged
lls_timeToRespond DURATION Time to respond to or acknowledge the alert

Displayed as Duration data type.

lls_category STRING Alert category
lls_severity STRING Alert severity
lls_comment STRING Comments you provide when acknowledging an alert