> Source: [sk180630](https://support.checkpoint.com/results/sk/sk180630)

# sk180630 - How to create basic alerts in Grafana for Skyline

| Property | Value |
|----------|-------|
| Solution ID | sk180630 |
| Date Created | 2023-02-13 |
| Last Modified | 2023-03-15 |
| Technical Level | General |
| Products | Security Gateway, Scalable Platforms, Security Management Server, Multi-Domain Security Management Server |
| Versions | R81.10 (EOS), R81 (EOS), R81.10 (EOS), R81 (EOS), R81.10 (EOS), R81 (EOS), R81 (EOS), R81.10 (EOS) |
| OS | Gaia |

## Solution

To create a new basic alert in the **CP Dashboard -** **Overview \& Alerts** for a specific metric, do these steps:  

1. Create a new graph that shows the required metric in the **CP Dashboard -** **Overview \& Alerts** .  
   **Note** : If the desired metric already has a graph in the **CP Dashboard -** **Overview \& Alerts** , skip this step and go to step # 2.  

   1. Go to **CP Dashboard - Overview \& Alerts** .  

      ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1676287711449/step1-alerts_dashboard202302131412381.jpg)  

   2. Add a new panel to the dashboard.  

      ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1676287711449/step2-new_panel202302131412532.jpg)  

      ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1676287711449/step3-new_panel2202302131413033.jpg)  

   3. Define a query to get the metric. For example: **avg by (environment, host_name)(100-system_cpu_utilization{state="idle"})** .  
      (Click on the image to enlarge it.) ![](https://sc1.checkpoint.com/sc//SolutionsStatics//NEW_SK_NOID1676287711449/step4-query202302131413124.jpg)   

   4. Add a title and description.  

      ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1676287711449/step5-title_description202302131413225.jpg)  

   5. Click **apply** .  

2. Create a new basic threshold alert for the newly added graph. In this example, we create a threshold-based alert for the last 5 minutes.  

   1. Select the newly created panel and click **Edit** .  

      ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1676287711449/step6-edit202302131413346.jpg)  

   2. Click on the **Alert** tab.  

      ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1676287711449/step7-alert_tab202302131413507.jpg)  

   3. Click on **Create alert rule from this panel** (if prompted, save the dashboard at this point).  

      ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1676287711449/step8-save_changes202302131414008.jpg)  

   4. Define the **Rule name** .  

      ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1676287711449/step9-rule_name202302131414209.jpg)  

   5. Create a folder for the alerts, or select an existing folder.  

      ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1676287711449/step10-folder2023021314143210.jpg)  

   6. Here we create a 3-tier query structure, where Query A -\> Query B -\> Query C.  
      1. **Query A**- created automatically. This is the panel's query.
      2. **Query B** - Reduces the data from Query A to perform math operations on it:  

         1. For the **Operation** , select **Reduce** .  

            ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1676287711449/step11-reduce2023021314144911.jpg)  

         2. Select **A** as the input.  

         3. Select **Last** as the function.  

         4. Keep the Mode as **Strict** .  

            ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1676287711449/step12-input2023021314145712.jpg)  

      3. Query C - Performs the math operation on Query B. In this scenario, it defines the threshold for the data.  

         1. Add a new query. Click on the **+Expression** button.  

         2. Select **Math** as the Operation.  

            ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1676287711449/step13-math2023021314150713.jpg)  

         3. In the text box below, add:  
            **$B\>60**   
            At this threshold, the alert is fired when the metric's value exceeds 60.  

   7. Define the alert's conditions:  

      1. Examine the last expression (Query C) - select C as the Condition.  

      2. Select the desired time for the evaluation of the query. In this example, we evaluate every 30 seconds (30s), and for 2 minutes (2m). This means that the alert is fired only if the condition is met (CPU utilization is \> 60 percent) in all samples of 2 minutes, at 30-second sampling intervals.  

         ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1676287711449/step14-condition2023021314151514.jpg)  

      3. Click **Preview Alerts** to make sure that your new alert works as expected.  

   8. Click the **Save and Exit** button (top-right).  

   9. Monitor your alert in the **Alerts Panel**.

<!-- -->

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
