Custom alerts
A custom alert is a type of notification that is generated for scheduled Data Explorer query runs.
The custom alerts feature allows you to monitor analyzed events that matters to you at regular intervals. You can view all custom alerts sent on the Custom Alerts page of the Arctic Wolf® Unified Portal. For more information, see:
To manage notification settings, see Custom alert rules.
Note:
- Custom alerts are considered non-emergency events for self-service reporting purposes only. This type of notification is configured by users in your organization. For more information, see Saved queries and custom alerts.
- Each custom alert provides a snapshot of the data that was captured for the time frame specified in the query. While this data never ages out of the custom alert itself, this data will only be available in Data Explorer up to your license limit. For more information, see Data Explorer license options.