I'm looking for a little help. I need to create a swql query to pull alert history for along with the notes entered for that alert. However I would also like to obtain the timestamp for those entries. The ultimately goal is to see how long it took for an alert to be triggered and how long the operator took to acknowledge and document all the entries with the alert notes section. Any help would be really appreciated
SELECT ao.alertconfigurations.Name as [AlertName], ah.AccountID, ah.Message, ao.EntityCaption, ao.RelatedNodeCaption, ao.TriggeredCount, ao.RealEntityType, ah.TimeStamp, ao.AlertNote, ao.LastTriggeredDateTime as [Note Date] FROM Orion.AlertHistory ah left join orion.alertobjects ao on ao.AlertObjectID=ah.AlertObjectID where ah.AccountID = 'user1' order by ah.timestamp desc