Determining the Content for a Watchdog Alert

The Watchdog alert leverages the Expression Editor (Building an Expression) to build alert conditions.

To determine the Content for a Watchdog alert:

  1. Open or create a Watchdog alert (Creating Alerts).
  2. Select the Content tab.
  3. In the Alert Definition box, click the specific conditions link. (For RL6:Infection, type in an expression.)
  4. From the Expression Editor dialog, set your conditions (Building an Expression). Click OK to save the expression and return to the Alert Properties window.
  5. Click OK to save and close the alert, or click another tab to continue making configurations.
  6. Note: FilesClosed located by a watchdog alert will only be included in alert notifications one time (files meeting the alert definition are placed on the BlacklistClosed. Other alert types allow you to include the file in the notification until that file no longer meets the alert definition requirements (Alert Properties).

Image from RL6:Risk:

Image from RL6:Infection: