Configuring the alert options for an alert group

The Alert options tab for an alert group contains general configuration options for the alert group.

Alert Options tab on the Create alert group dialog

To configure the alert options:

  1. From the Select data source drop-down list, select the data source to use for the EQL query.

    The drop-down list only contains data sources belonging to the application's data source family.

  2. In the Alert Options section:
    Field Description
    Alert group display name Required. In the field, type the name of the alert group. This is the name that displays to end users.
    Expand alert group by default If this checkbox is checked, then when end users display the alerts list, the alert group is automatically expanded to show the individual alerts.

    If the box is not checked, then the alert group is closed.

    Alerts component showing expanded and collapsed groups on the end user view

    By default, this box is not checked.

    Enable refinement by alerts If this checkbox is checked, then the alert messages are hyperlinked. When end users click the alert message, the data is refined to only show the records that the alert applies to.

    By default, this checkbox is checked.

    Note that end users can only refine the data using attributes that are present in the physical data. If your EQL query for the alert only contains derived or aliased attributes, then end users cannot use the alert to refine the data, and the alert messages are not hyperlinked.

    If you uncheck the box, then the Target page to display refinement field is disabled.

    Target page to display refinement If you are allowing end users to use the alert message to refine the data, then in this field, type the name of the page to display when users click the alert message.

    If you do not provide a page name, then the end user stays on the same page.

    For information on configuring a page transition, see Page transition syntax.

    Maximum alerts to display Type the maximum number of alerts to display in the alert group. If the number of alerts is greater than this number, then end users cannot see the remaining alerts.

    The default value is 10.