SWQL Library
Alerts
Aggregation
POLARISNOC Certified

Top 10 Most Frequent Alerts

What this query does

Identify which alert definitions are firing the most to prioritize tuning

SWQL Query
SELECT TOP 10 Name, COUNT(*) AS TriggerCount,
       MAX(TriggeredDateTime) AS LastTriggered,
       AVG(TriggeredCount) AS AvgTriggerCount
FROM Orion.AlertActive
GROUP BY Name
ORDER BY TriggerCount DESC
alerts
tuning
top 10
aggregation
Source:POLARISNOCยท POLARISNOC Original

Unlock the full POLARISNOC hub

AI-powered SWQL generation, script management, CVE tracking, and verified solution intelligence.

Sign Up Free