I have an alert for my end user computing group setup as follows:

Which I meant to be as, if the application tag matches any of the four listed above AND its severity is average or higher OR the notify tag equals app_owners, send the alert to the euc group.
They are receiving an alert where the notify:app_owners tag is present but the application tag does not match any of the ones listed above.

Any thoughts?
Which I meant to be as, if the application tag matches any of the four listed above AND its severity is average or higher OR the notify tag equals app_owners, send the alert to the euc group.
They are receiving an alert where the notify:app_owners tag is present but the application tag does not match any of the ones listed above.
Any thoughts?
Comment