<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can i add alert to my search query using trigger condition alert in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/How-can-i-add-alert-to-my-search-query-using-trigger-condition/m-p/569678#M13083</link>
    <description>&lt;P&gt;here is my original query&lt;BR /&gt;| eval amd-eu1=if(like(namespace, "amd-eu1"), 1,0),&lt;BR /&gt;amd-eu2=if(like(namespace, "amd-eu2"), 1,0), amd-eu3=if(like(namespace, "amd-eu3"), 1,0), amd-eu4=if(like(namespace, "amd-eu4"), 1,0),&lt;BR /&gt;amd-eu5=if(like(namespace, "amd-eu5"), 1,0), amd-ap1=if(like(namespace, "amd-ap1"), 1,0), amd-am1=if(like(namespace, "amd-am1"), 1,0)&lt;BR /&gt;| stats sum(amd-eu1) as AMD_EU1, sum(amd-eu2) as AMD_EU2, sum(amd-eu3) as AMD_EU3, sum(amd-eu4) as AMD_EU4, sum(amd-eu5) as AMD_EU5, sum(amd-ap1) as AMD_AP1, sum(amd-am1) as AMD_AM1&lt;BR /&gt;&lt;BR /&gt;i have remove the table&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 05 Oct 2021 11:59:31 GMT</pubDate>
    <dc:creator>neilfajardo15</dc:creator>
    <dc:date>2021-10-05T11:59:31Z</dc:date>
    <item>
      <title>How can i add alert to my search query using trigger condition alert</title>
      <link>https://community.splunk.com/t5/Alerting/How-can-i-add-alert-to-my-search-query-using-trigger-condition/m-p/569660#M13078</link>
      <description>&lt;P&gt;Hi, Im setting up an alert for data flow the alert build is when the application is not running it will send us an alert and i use trigger condition in the alert.&amp;nbsp;&lt;BR /&gt;here is the search query&amp;nbsp;&lt;BR /&gt;| eval value1=if(like(sample, "value1"), 1,0), value2=if(like(sample, "value2"), 1,0), value3=if(like(sample, "value3"), 1,0)&lt;BR /&gt;| stats sum(value1) as VALUE1, sum(value2) as VALUE2, sum(value3) as VALUE3&lt;BR /&gt;| table VALUE1, VALUE2, VALUE3&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;and for the alert condition i use this command&amp;nbsp;&lt;BR /&gt;search VALUE1 = 0&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;"0" because in the sum it indicates that the 0 means data is not flowing in splunk meaning the application is down&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 10:01:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-can-i-add-alert-to-my-search-query-using-trigger-condition/m-p/569660#M13078</guid>
      <dc:creator>neilfajardo15</dc:creator>
      <dc:date>2021-10-05T10:01:16Z</dc:date>
    </item>
    <item>
      <title>Re: How can i add alert to my search query using trigger condition alert</title>
      <link>https://community.splunk.com/t5/Alerting/How-can-i-add-alert-to-my-search-query-using-trigger-condition/m-p/569661#M13079</link>
      <description>&lt;P&gt;You might want to use&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| where VALUE1=0&lt;/LI-CODE&gt;&lt;P&gt;then you can alert on whether there are any results or not&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 10:13:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-can-i-add-alert-to-my-search-query-using-trigger-condition/m-p/569661#M13079</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-10-05T10:13:09Z</dc:date>
    </item>
    <item>
      <title>Re: How can i add alert to my search query using trigger condition alert</title>
      <link>https://community.splunk.com/t5/Alerting/How-can-i-add-alert-to-my-search-query-using-trigger-condition/m-p/569667#M13080</link>
      <description>&lt;P&gt;Hi thanks for the answer, but im still not able to receive alerts &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; im using email alerts&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 10:55:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-can-i-add-alert-to-my-search-query-using-trigger-condition/m-p/569667#M13080</guid>
      <dc:creator>neilfajardo15</dc:creator>
      <dc:date>2021-10-05T10:55:16Z</dc:date>
    </item>
    <item>
      <title>Re: How can i add alert to my search query using trigger condition alert</title>
      <link>https://community.splunk.com/t5/Alerting/How-can-i-add-alert-to-my-search-query-using-trigger-condition/m-p/569670#M13081</link>
      <description>&lt;P&gt;How have you set up your alerts?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 11:40:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-can-i-add-alert-to-my-search-query-using-trigger-condition/m-p/569670#M13081</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-10-05T11:40:14Z</dc:date>
    </item>
    <item>
      <title>Re: How can i add alert to my search query using trigger condition alert</title>
      <link>https://community.splunk.com/t5/Alerting/How-can-i-add-alert-to-my-search-query-using-trigger-condition/m-p/569672#M13082</link>
      <description>&lt;P&gt;I use this and it is realtime&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="neilfajardo15_0-1633434243428.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16276iF35815A0DC66C7D4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="neilfajardo15_0-1633434243428.png" alt="neilfajardo15_0-1633434243428.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 11:44:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-can-i-add-alert-to-my-search-query-using-trigger-condition/m-p/569672#M13082</guid>
      <dc:creator>neilfajardo15</dc:creator>
      <dc:date>2021-10-05T11:44:26Z</dc:date>
    </item>
    <item>
      <title>Re: How can i add alert to my search query using trigger condition alert</title>
      <link>https://community.splunk.com/t5/Alerting/How-can-i-add-alert-to-my-search-query-using-trigger-condition/m-p/569678#M13083</link>
      <description>&lt;P&gt;here is my original query&lt;BR /&gt;| eval amd-eu1=if(like(namespace, "amd-eu1"), 1,0),&lt;BR /&gt;amd-eu2=if(like(namespace, "amd-eu2"), 1,0), amd-eu3=if(like(namespace, "amd-eu3"), 1,0), amd-eu4=if(like(namespace, "amd-eu4"), 1,0),&lt;BR /&gt;amd-eu5=if(like(namespace, "amd-eu5"), 1,0), amd-ap1=if(like(namespace, "amd-ap1"), 1,0), amd-am1=if(like(namespace, "amd-am1"), 1,0)&lt;BR /&gt;| stats sum(amd-eu1) as AMD_EU1, sum(amd-eu2) as AMD_EU2, sum(amd-eu3) as AMD_EU3, sum(amd-eu4) as AMD_EU4, sum(amd-eu5) as AMD_EU5, sum(amd-ap1) as AMD_AP1, sum(amd-am1) as AMD_AM1&lt;BR /&gt;&lt;BR /&gt;i have remove the table&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 11:59:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-can-i-add-alert-to-my-search-query-using-trigger-condition/m-p/569678#M13083</guid>
      <dc:creator>neilfajardo15</dc:creator>
      <dc:date>2021-10-05T11:59:31Z</dc:date>
    </item>
    <item>
      <title>Re: How can i add alert to my search query using trigger condition alert</title>
      <link>https://community.splunk.com/t5/Alerting/How-can-i-add-alert-to-my-search-query-using-trigger-condition/m-p/569681#M13084</link>
      <description>&lt;P&gt;Rather than custom, can you use number of results returned by the search?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 12:13:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-can-i-add-alert-to-my-search-query-using-trigger-condition/m-p/569681#M13084</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-10-05T12:13:05Z</dc:date>
    </item>
    <item>
      <title>Re: How can i add alert to my search query using trigger condition alert</title>
      <link>https://community.splunk.com/t5/Alerting/How-can-i-add-alert-to-my-search-query-using-trigger-condition/m-p/569688#M13085</link>
      <description>&lt;P&gt;But due to the stats sum and the value inside it a table will be created then it will be a result for the search&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 12:43:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-can-i-add-alert-to-my-search-query-using-trigger-condition/m-p/569688#M13085</guid>
      <dc:creator>neilfajardo15</dc:creator>
      <dc:date>2021-10-05T12:43:46Z</dc:date>
    </item>
    <item>
      <title>Re: How can i add alert to my search query using trigger condition alert</title>
      <link>https://community.splunk.com/t5/Alerting/How-can-i-add-alert-to-my-search-query-using-trigger-condition/m-p/569693#M13087</link>
      <description>&lt;P&gt;Put the where as part of your search rather than the custom condition on the alert&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 12:53:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-can-i-add-alert-to-my-search-query-using-trigger-condition/m-p/569693#M13087</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-10-05T12:53:19Z</dc:date>
    </item>
    <item>
      <title>Re: How can i add alert to my search query using trigger condition alert</title>
      <link>https://community.splunk.com/t5/Alerting/How-can-i-add-alert-to-my-search-query-using-trigger-condition/m-p/569829#M13091</link>
      <description>&lt;P&gt;Hi, Sorry for the late reply the alert works but it was spamming a lot of mail and also even though the data is flowing it is still alerting&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Oct 2021 06:08:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-can-i-add-alert-to-my-search-query-using-trigger-condition/m-p/569829#M13091</guid>
      <dc:creator>neilfajardo15</dc:creator>
      <dc:date>2021-10-06T06:08:22Z</dc:date>
    </item>
  </channel>
</rss>

