
Format of alert messages
Once content-based alerts have been created, SSB will send alert messages to the
configured targets.
The alert email's subject line will follow this format:
Alert: [myalert][mylogspace]
Alert messages will be presented in the following format:
Alert: There were at least 10000 matches between Mon 18 Apr 2016 10:45:38 CEST and Mon
18 Apr 2016 10:45:43 CEST on
* logspace: "<mylogspace>"
* alert: "<myalert>"
* search expression: "<mysearchexpression>"
To review these matches on your SSB appliance, see:
https://<IP_address_of_SSB>:<port_number>/index.php?_backend=SearchLogspace#logspace_
name=mylogspace&
from=1460976338&to=1460976343&search_expression=mysearchexpression
Note: You will not receive a new alert message for a cooldown period of 1 minute for
this alert.
Note that the contents of the log messages are not shared in the alert message. A URL is
provided to direct users to their SSB appliance.
SSB 5.3.0 User Guide
Creating content-based alerts
44