Skip to content

Monitors

Monitors let you save search filters as persistent, reusable alert conditions. This is useful for modeling custom alerts that Nzyme does not support out of the box.

A user must have the Manage Monitoring permission of a subsystem to configure related monitors. Any user can manually load monitors as filters and perform manual searches.

How Monitors Work

Every minute, Nzyme checks whether any monitor is due to run, based on its configured Interval. The default Interval is 1 minute, meaning the monitor executes every minute.

When a monitor runs, Nzyme performs a search using the configured filters and triggers a detection event when the result count exceeds the configured Trigger Condition.

Creating a Monitor

You can create a monitor from any supported search page by clicking Save as new Monitor, provided your user has the required permissions.

Editing Monitors

There are two ways to edit a monitor, depending on what you want to change.

Editing the Filter and Tap Selection

To change a monitor's filters or tap selection, open the search page and click Load Existing Monitor. Adjust the filters using the standard filter configuration and the taps using the standard tap selector, then click Save Monitor to overwrite the loaded monitor.

Editing the Monitor Configuration

To change monitor parameters such as name, description, interval, lookback, or trigger condition, open the monitor from the subsystem's monitors page and click Edit Monitor.

Alert and Event Generation

Monitors generate detection events of type MONITOR_TRIGGERED when the search result count exceeds the configured Trigger Condition.