Edit a custom alert rule
If custom alert settings were enabled for a saved query, you can edit those settings from the Alert Configuration Rules page of the Unified Portal. You can also modify the name of the query and its description.
Note:
- A maximum of 10 custom alert rules can be enabled at the same time. If you have reached this limit, you will be unable to save your changes. To avoid this error, disable another custom alert rule before you begin.
- If you want to change the saved query linked to a custom alert rule, for example, to change Data Explorer field values or query operators, see Edit a saved query instead.
- Sign in to the Arctic Wolf Unified Portal.
- In the navigation menu, click .
- Click the Custom Alert Rules tab.
- Find the custom alert rule that you want to edit.
- Optional: To narrow the list of rules, in the Search field, enter a search term.
- For the desired custom alert rule, click .
- Optional: In the Saved Query Settings section:
- In the Custom Alert Settings section:
- Click
Save.