<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Alert when &amp;quot;rises by&amp;quot; issue in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Alert-when-quot-rises-by-quot-issue/m-p/50928#M685</link>
    <description>&lt;P&gt;Hey HB.&lt;BR /&gt;
I cannot tell from your question if the search ran automatically (scheduled) the first time or not but, the way rises by works is this:&lt;/P&gt;

&lt;P&gt;Day 0: You automatically run a search and get 5 results&lt;BR /&gt;
Day 1: You decide to schedule this search and alert you if the events rise. This search returns 8 results but will not alert you, because there is no baseline for this search to compare the 8 results to.&lt;BR /&gt;
Day 2: The search runs again, this time returning 10 events, and SHOULD alert you, since 10 -8 = 2 &amp;gt;1. In this second scheduled run, there is a baseline of 8 to compare to and an alert should be triggered.&lt;/P&gt;

&lt;P&gt;If this is not the behavior you are seeing then you might want to test your email alerting capabilities. If those are working, then perhaps a case with our support should be opened and a diag attached to the case.&lt;/P&gt;

&lt;P&gt;Hope this helps,&lt;BR /&gt;
Cheers!&lt;BR /&gt;
.gz&lt;/P&gt;</description>
    <pubDate>Thu, 16 Sep 2010 05:20:49 GMT</pubDate>
    <dc:creator>Genti</dc:creator>
    <dc:date>2010-09-16T05:20:49Z</dc:date>
    <item>
      <title>Alert when "rises by" issue</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-when-quot-rises-by-quot-issue/m-p/50927#M684</link>
      <description>&lt;P&gt;Hi.
I have scheduled a search to run on midnight, and I need to send a mail if the number of returned events is greater than the day before.
I've configured this:
  Schedule type: Basic
  Run every:     Day at midnight&lt;/P&gt;

&lt;P&gt;Alert conditions
  Perform actions: If number of events
  Rises by  1&lt;/P&gt;

&lt;P&gt;Alert actions
  Send email&lt;/P&gt;

&lt;P&gt;Either I've misinterpreted the "rises by" setting, or it's not working. Because I've run the search yesterday getting 6 events, and run it today and I've got 9 events, but splunk didn't send the alert.
Any thoughts?&lt;/P&gt;</description>
      <pubDate>Wed, 15 Sep 2010 20:53:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-when-quot-rises-by-quot-issue/m-p/50927#M684</guid>
      <dc:creator>hbazan</dc:creator>
      <dc:date>2010-09-15T20:53:12Z</dc:date>
    </item>
    <item>
      <title>Re: Alert when "rises by" issue</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-when-quot-rises-by-quot-issue/m-p/50928#M685</link>
      <description>&lt;P&gt;Hey HB.&lt;BR /&gt;
I cannot tell from your question if the search ran automatically (scheduled) the first time or not but, the way rises by works is this:&lt;/P&gt;

&lt;P&gt;Day 0: You automatically run a search and get 5 results&lt;BR /&gt;
Day 1: You decide to schedule this search and alert you if the events rise. This search returns 8 results but will not alert you, because there is no baseline for this search to compare the 8 results to.&lt;BR /&gt;
Day 2: The search runs again, this time returning 10 events, and SHOULD alert you, since 10 -8 = 2 &amp;gt;1. In this second scheduled run, there is a baseline of 8 to compare to and an alert should be triggered.&lt;/P&gt;

&lt;P&gt;If this is not the behavior you are seeing then you might want to test your email alerting capabilities. If those are working, then perhaps a case with our support should be opened and a diag attached to the case.&lt;/P&gt;

&lt;P&gt;Hope this helps,&lt;BR /&gt;
Cheers!&lt;BR /&gt;
.gz&lt;/P&gt;</description>
      <pubDate>Thu, 16 Sep 2010 05:20:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-when-quot-rises-by-quot-issue/m-p/50928#M685</guid>
      <dc:creator>Genti</dc:creator>
      <dc:date>2010-09-16T05:20:49Z</dc:date>
    </item>
    <item>
      <title>Re: Alert when "rises by" issue</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-when-quot-rises-by-quot-issue/m-p/50929#M686</link>
      <description>&lt;P&gt;Hi Genti.&lt;BR /&gt;
I think I've found the issue. If I go to Jobs and filter this saved search, the number of events for last two runs says "0", but if I open the results I do have events (but above the flashtimeline says "0 matching events"). And if I re-run the search (on the same window) the results I got the same results but the "matching events" is right. Maybe that's what's avoiding the alarm to run?&lt;/P&gt;</description>
      <pubDate>Thu, 16 Sep 2010 20:47:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-when-quot-rises-by-quot-issue/m-p/50929#M686</guid>
      <dc:creator>hbazan</dc:creator>
      <dc:date>2010-09-16T20:47:12Z</dc:date>
    </item>
  </channel>
</rss>

