<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Alert settings menu: What's the difference between &amp;quot;Per-Result&amp;quot; and &amp;quot;Number of Results&amp;quot; options? in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Alert-settings-menu-What-s-the-difference-between-quot-Per/m-p/328472#M5825</link>
    <description>&lt;P&gt;Hey @ddrillic, It looks like the &lt;A href="http://docs.splunk.com/Documentation/Splunk/7.0.0/Alert/Alertexamples"&gt;Number of Results&lt;/A&gt; triggers based on custom # of results. &lt;BR /&gt;
 Select Save As &amp;gt; Alert.&lt;BR /&gt;
Specify the following values for the fields in the Save As Alert dialog box.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;    Title: Errors in the last 24 hours
    Alert type: Scheduled
    Time Range: Run every day
    Schedule: At 10:00
    Trigger condition: Number of Results
    Trigger when number of results: is greater than 5.

Select the Send Email alert action.
Set the following email settings, using tokens in the Subject and Message fields.

    To: email recipient
    Priority: Normal
    Subject: Too many errors alert: $name$
    Message: There were $job.resultCount$ errors reported on $trigger_date$.
    Include: Link to Alert and Link to Results
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;And &lt;A href="http://docs.splunk.com/Documentation/Splunk/7.0.0/Alert/AlertTypesOverview"&gt;per-result&lt;/A&gt; triggers every time there is a search result, although you can specify a time period and optional field values for suppression. &lt;/P&gt;</description>
    <pubDate>Fri, 27 Oct 2017 18:26:08 GMT</pubDate>
    <dc:creator>lfedak_splunk</dc:creator>
    <dc:date>2017-10-27T18:26:08Z</dc:date>
    <item>
      <title>Alert settings menu: What's the difference between "Per-Result" and "Number of Results" options?</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-settings-menu-What-s-the-difference-between-quot-Per/m-p/328471#M5824</link>
      <description>&lt;P&gt;What's the difference between alerts' &lt;STRONG&gt;Per-Result&lt;/STRONG&gt; and the &lt;STRONG&gt;Number of Results&lt;/STRONG&gt; options?&lt;/P&gt;

&lt;P&gt;We are not clear about the difference between them.&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/3716i041F2C581601F7F9/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;When we set it up like this, we get alerts from August. Why is that?&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/3717iBA4BF261729F66BB/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Oct 2017 16:44:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-settings-menu-What-s-the-difference-between-quot-Per/m-p/328471#M5824</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2017-10-27T16:44:53Z</dc:date>
    </item>
    <item>
      <title>Re: Alert settings menu: What's the difference between "Per-Result" and "Number of Results" options?</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-settings-menu-What-s-the-difference-between-quot-Per/m-p/328472#M5825</link>
      <description>&lt;P&gt;Hey @ddrillic, It looks like the &lt;A href="http://docs.splunk.com/Documentation/Splunk/7.0.0/Alert/Alertexamples"&gt;Number of Results&lt;/A&gt; triggers based on custom # of results. &lt;BR /&gt;
 Select Save As &amp;gt; Alert.&lt;BR /&gt;
Specify the following values for the fields in the Save As Alert dialog box.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;    Title: Errors in the last 24 hours
    Alert type: Scheduled
    Time Range: Run every day
    Schedule: At 10:00
    Trigger condition: Number of Results
    Trigger when number of results: is greater than 5.

Select the Send Email alert action.
Set the following email settings, using tokens in the Subject and Message fields.

    To: email recipient
    Priority: Normal
    Subject: Too many errors alert: $name$
    Message: There were $job.resultCount$ errors reported on $trigger_date$.
    Include: Link to Alert and Link to Results
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;And &lt;A href="http://docs.splunk.com/Documentation/Splunk/7.0.0/Alert/AlertTypesOverview"&gt;per-result&lt;/A&gt; triggers every time there is a search result, although you can specify a time period and optional field values for suppression. &lt;/P&gt;</description>
      <pubDate>Fri, 27 Oct 2017 18:26:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-settings-menu-What-s-the-difference-between-quot-Per/m-p/328472#M5825</guid>
      <dc:creator>lfedak_splunk</dc:creator>
      <dc:date>2017-10-27T18:26:08Z</dc:date>
    </item>
    <item>
      <title>Re: Alert settings menu: What's the difference between "Per-Result" and "Number of Results" options?</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-settings-menu-What-s-the-difference-between-quot-Per/m-p/328473#M5826</link>
      <description>&lt;P&gt;About the alerts from August. Maybe they got stuck in the Unix mail queues - how do we clear them, if that's the case?&lt;/P&gt;</description>
      <pubDate>Sat, 28 Oct 2017 01:57:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-settings-menu-What-s-the-difference-between-quot-Per/m-p/328473#M5826</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2017-10-28T01:57:55Z</dc:date>
    </item>
    <item>
      <title>Re: Alert settings menu: What's the difference between "Per-Result" and "Number of Results" options?</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-settings-menu-What-s-the-difference-between-quot-Per/m-p/328474#M5827</link>
      <description>&lt;P&gt;Thank you @lfedak!&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2017 22:46:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-settings-menu-What-s-the-difference-between-quot-Per/m-p/328474#M5827</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2017-10-30T22:46:38Z</dc:date>
    </item>
  </channel>
</rss>

