About alert groups

Alerts are displayed within alert groups.

Each alert group requires an EQL query to retrieve a set of matching records. The records are grouped by one or more attributes.

If the query does not return any records, then there are no alerts for that alert group, and the group does not display to end users.

If there are matching records, then there is a separate alert for each attribute value for the group-by attribute. For example, if an alert is being displayed when the average price of wine within a single region is greater than $50, then there is a separate alert for each region.