Hi everyone,
I am having trouble creating a custom alert for a host sending a large amount (over 1GB) of traffic externally. I can create a log query showing top assets with outbound traffic but could not find a way to create a trigger that would filter on aggregate functions. Something similar to HAVING clause in SQL.
Any ideas?
Thanks!