Reducing noise by using advanced log alert filters
Advanced alert filters reduce noise by dropping alerts that do not indicate a significant issue.
You use an advanced log alert filter to determine whether to drop or allow an alert. For example, you can define a filter that drops (discards) alerts that come from particular sources or alerts for anomalies that do not cross a specified threshold.
Some examples of the actions that advanced filters can enable:
- Alert only on anomalies shared across multiple hosts.
- Do not alert on anomalies that happen outside of working hours.
- Do not alert if the anomaly amplitude does not cross the specified threshold.
- Alert only on anomalies that are part of a correlation.
For deeper technical information on log alert filters, see the Advanced Log Alert Filtering [KB0863538] article in the Now Support Knowledge Base.