<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Creating an alert using the result obtained in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Creating-an-alert-using-the-result-obtained/m-p/322255#M10852</link>
    <description>&lt;P&gt;Superb elliotproebstel ! Thanks a ton.&lt;/P&gt;</description>
    <pubDate>Mon, 09 Apr 2018 04:44:48 GMT</pubDate>
    <dc:creator>Nidheesh</dc:creator>
    <dc:date>2018-04-09T04:44:48Z</dc:date>
    <item>
      <title>Creating an alert using the result obtained</title>
      <link>https://community.splunk.com/t5/Alerting/Creating-an-alert-using-the-result-obtained/m-p/322253#M10850</link>
      <description>&lt;P&gt;I have this query to return the server whose event count is less than 10 during a time interval.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=np_dss (source="DSS:DATA" OR source="DSS:DATAHUB") | stats count by host | where count&amp;lt;10 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This query returns 2 servers N01APL100 &amp;amp; N01APL101 of the total 3 servers, N01APL100, N01APL101, N01APL102.&lt;/P&gt;

&lt;P&gt;All I need is to create an alert that must include the servers returned in the response (N01APL100 &amp;amp; N01APL101) are low in event count.&lt;/P&gt;

&lt;P&gt;&lt;EM&gt;Eg&lt;/EM&gt;: &lt;STRONG&gt;Server/s N01APL100 &amp;amp; N01APL101 are low in event count.&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;Can someone please help?&lt;/P&gt;</description>
      <pubDate>Fri, 06 Apr 2018 11:10:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Creating-an-alert-using-the-result-obtained/m-p/322253#M10850</guid>
      <dc:creator>Nidheesh</dc:creator>
      <dc:date>2018-04-06T11:10:53Z</dc:date>
    </item>
    <item>
      <title>Re: Creating an alert using the result obtained</title>
      <link>https://community.splunk.com/t5/Alerting/Creating-an-alert-using-the-result-obtained/m-p/322254#M10851</link>
      <description>&lt;P&gt;If you append this to your search, you can alert if the result count is greater than 0 and reference the field &lt;CODE&gt;$result.message$&lt;/CODE&gt; in your alert text.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| stats values(host) AS host 
| eval host=mvjoin(host, " &amp;amp; "), message="Server/s ".host." are low in event count." 
| fields message
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 06 Apr 2018 13:02:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Creating-an-alert-using-the-result-obtained/m-p/322254#M10851</guid>
      <dc:creator>elliotproebstel</dc:creator>
      <dc:date>2018-04-06T13:02:31Z</dc:date>
    </item>
    <item>
      <title>Re: Creating an alert using the result obtained</title>
      <link>https://community.splunk.com/t5/Alerting/Creating-an-alert-using-the-result-obtained/m-p/322255#M10852</link>
      <description>&lt;P&gt;Superb elliotproebstel ! Thanks a ton.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Apr 2018 04:44:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Creating-an-alert-using-the-result-obtained/m-p/322255#M10852</guid>
      <dc:creator>Nidheesh</dc:creator>
      <dc:date>2018-04-09T04:44:48Z</dc:date>
    </item>
  </channel>
</rss>

