EM12cR3 incidents rules - when is the critical metric alert triggered for failed logins?
Does anyone understand how the out of the box 'Incident management rule set for all targets' triggers an incident for failed logins? I have set my metric thresholds for the database, made sure auditing is on and that failed logins are captured in the dba_audit_trail table. When I test with a scenario that I believe should trigger an incident, I have no success.
Has anyone found some helpful documentation on how each metric is triggered?
Regards,
Marg