Limiting the complexity of queries in alert investigation mode

When investigating an alert, the complexity of SQL queries for event filtering is limited if the Related to alert option is selected in the drop-down list of event sources. If this is the case, only the functions and operators listed below are available for event filtering.

If the All events option is selected from the drop-down list of event sources, these limitations do not apply.

When filtering by alert-related events in alert investigation mode, you cannot perform operations on the data of event fields or assign names to the columns of displayed data.

Page top