#all I’m stuck with alerting issue
I’m trying to run the query as below
fields eventName
| filter eventName =~ /DeleteBucket|DeleteBucketLifecycle|DeleteBucketPolicy|DeleteBucketReplication|DeleteBucketTagging|PutBucketLifecycle|PutBucketPolicy/
| stats count(*) by eventName
now the question is how to trigger an alarm when any event happens out of the mentioned eventNames with other info in alert message like Account Id, InstanceId etc.
Please help