<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Search Query - Alert in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Search-Query-Alert/m-p/496537#M8845</link>
    <description>&lt;P&gt;thank you rashi83&lt;/P&gt;</description>
    <pubDate>Tue, 12 May 2020 21:19:46 GMT</pubDate>
    <dc:creator>to4kawa</dc:creator>
    <dc:date>2020-05-12T21:19:46Z</dc:date>
    <item>
      <title>Search Query - Alert</title>
      <link>https://community.splunk.com/t5/Alerting/Search-Query-Alert/m-p/496528#M8836</link>
      <description>&lt;P&gt;Hi , &lt;BR /&gt;I have a query which returns 5 events ( basically 5 files gets transferred) . I need to send an alert once all 5 files are transferred - meaning as soon as the event count is 5 , alert should be triggered. IS the below query good enough for such scneario ?&lt;/P&gt;
&lt;P&gt;Should I write like index=* X y | stats count by FileName | where count=5&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jun 2020 21:04:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Search-Query-Alert/m-p/496528#M8836</guid>
      <dc:creator>rashi83</dc:creator>
      <dc:date>2020-06-09T21:04:26Z</dc:date>
    </item>
    <item>
      <title>Re: Search Query - Alert</title>
      <link>https://community.splunk.com/t5/Alerting/Search-Query-Alert/m-p/496529#M8837</link>
      <description>&lt;P&gt;Does only success populate the event?&lt;/P&gt;</description>
      <pubDate>Tue, 12 May 2020 20:36:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Search-Query-Alert/m-p/496529#M8837</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-05-12T20:36:24Z</dc:date>
    </item>
    <item>
      <title>Re: Search Query - Alert</title>
      <link>https://community.splunk.com/t5/Alerting/Search-Query-Alert/m-p/496530#M8838</link>
      <description>&lt;P&gt;yes , if only success / transfer happen - event gets written&lt;/P&gt;</description>
      <pubDate>Tue, 12 May 2020 20:38:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Search-Query-Alert/m-p/496530#M8838</guid>
      <dc:creator>rashi83</dc:creator>
      <dc:date>2020-05-12T20:38:24Z</dc:date>
    </item>
    <item>
      <title>Re: Search Query - Alert</title>
      <link>https://community.splunk.com/t5/Alerting/Search-Query-Alert/m-p/496531#M8839</link>
      <description>&lt;P&gt;well, your query is enough for this, I think.&lt;/P&gt;</description>
      <pubDate>Tue, 12 May 2020 20:49:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Search-Query-Alert/m-p/496531#M8839</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-05-12T20:49:33Z</dc:date>
    </item>
    <item>
      <title>Re: Search Query - Alert</title>
      <link>https://community.splunk.com/t5/Alerting/Search-Query-Alert/m-p/496532#M8840</link>
      <description>&lt;P&gt;So while setting up Alert - should I mention Trigger Alert when Number of Results is greater than 4. OR will the query takes care of it. &lt;/P&gt;

&lt;P&gt;I am little confused .&lt;/P&gt;</description>
      <pubDate>Tue, 12 May 2020 20:55:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Search-Query-Alert/m-p/496532#M8840</guid>
      <dc:creator>rashi83</dc:creator>
      <dc:date>2020-05-12T20:55:41Z</dc:date>
    </item>
    <item>
      <title>Re: Search Query - Alert</title>
      <link>https://community.splunk.com/t5/Alerting/Search-Query-Alert/m-p/496533#M8841</link>
      <description>&lt;P&gt;you use &lt;CODE&gt;| where count=5&lt;/CODE&gt;&lt;BR /&gt;
, so to fire&lt;BR /&gt;
alert&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;event count &amp;gt; 0
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 12 May 2020 20:59:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Search-Query-Alert/m-p/496533#M8841</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-05-12T20:59:25Z</dc:date>
    </item>
    <item>
      <title>Re: Search Query - Alert</title>
      <link>https://community.splunk.com/t5/Alerting/Search-Query-Alert/m-p/496534#M8842</link>
      <description>&lt;P&gt;Thank you &lt;/P&gt;</description>
      <pubDate>Tue, 12 May 2020 21:01:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Search-Query-Alert/m-p/496534#M8842</guid>
      <dc:creator>rashi83</dc:creator>
      <dc:date>2020-05-12T21:01:58Z</dc:date>
    </item>
    <item>
      <title>Re: Search Query - Alert</title>
      <link>https://community.splunk.com/t5/Alerting/Search-Query-Alert/m-p/496535#M8843</link>
      <description>&lt;P&gt;please provide your query for answer and accept it.&lt;/P&gt;</description>
      <pubDate>Tue, 12 May 2020 21:05:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Search-Query-Alert/m-p/496535#M8843</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-05-12T21:05:36Z</dc:date>
    </item>
    <item>
      <title>Re: Search Query - Alert</title>
      <link>https://community.splunk.com/t5/Alerting/Search-Query-Alert/m-p/496536#M8844</link>
      <description>&lt;P&gt;up voted your answer&lt;/P&gt;</description>
      <pubDate>Tue, 12 May 2020 21:12:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Search-Query-Alert/m-p/496536#M8844</guid>
      <dc:creator>rashi83</dc:creator>
      <dc:date>2020-05-12T21:12:54Z</dc:date>
    </item>
    <item>
      <title>Re: Search Query - Alert</title>
      <link>https://community.splunk.com/t5/Alerting/Search-Query-Alert/m-p/496537#M8845</link>
      <description>&lt;P&gt;thank you rashi83&lt;/P&gt;</description>
      <pubDate>Tue, 12 May 2020 21:19:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Search-Query-Alert/m-p/496537#M8845</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-05-12T21:19:46Z</dc:date>
    </item>
  </channel>
</rss>

