I am trying to create an alert for Unbound recursion time. I found an application alerting article that was very helpful, but I’ve been unable to get the Unbound alert to work.
I’ve left the >0 just to make it fire, there is no match when using the debug:
Rule name: Unbound recursion time increased
Alert rule: application_metrics.app_id = “unbound-recursiontime” AND (application_metrics.metric = “avg” AND application_metrics.value > 0)
Alert query: SELECT * FROM devices,applications,application_metrics WHERE (devices.device_id = ? AND devices.device_id = applications.device_id AND applications.app_id = application_metrics.app_id) AND application_metrics.app_id = “unbound-recursiontime” AND (application_metrics.metric = “avg” AND application_metrics.value > 0)
Rule match: no match
For reference, this is the article I found for application alerting: