Feature Idea: Automatically change NRQL query in events

Hello everyone

I have an NRQL query policy for alerts, like this:
SELECT count(*) FROM Log WHERE hostname = ‘myapplication.com’ AND message LIKE ‘%error%’

when I click the details of the event to go to Insights, it will give the query like this:
SELECT count(*) FROM Log WHERE hostname = ‘myapplication.com’ AND message LIKE ‘%error%’ TIMESERIES 1 minute SINCE ‘2020-12-28 16:07:10’ UNTIL ‘2020-12-28 22:06:10’

I do not want the count, I want it to be changed automatically to something like this with the Timestamp
SELECT message FROM Log WHERE hostname = ‘myapplication.com’ AND message LIKE ‘%error%’ SINCE ‘2020-12-28 16:07:10’ UNTIL ‘2020-12-28 22:06:10’

New Relic edit

  • I want this, too
  • I have more info to share (reply below)
  • I have a solution for this

0 voters

We take feature ideas seriously and our product managers review every one when plotting their roadmaps. However, there is no guarantee this feature will be implemented. This post ensures the idea is put on the table and discussed though. So please vote and share your extra details with our team.

Hi @proplab, I’ll be happy to submit a feature request for this. However, you could try modifying the NRQL alert query itself to include facet message. That will show you the error message causing the violation.

1 Like

Hi @zahrasiddiqa
Thanks for your reply

I added “facet message” as you suggest, but in Insights, it will give me the chart, not the log immediately

here is my example:

Hi @proplab, I have followed up on this and submitted the feature idea. I will update this thread once our product development team review it and give their feedback. There is no guarantee that this will be implemented however.

1 Like