Alert if number of events drops by


I'm making a query that should fire if the number of events goes down by 1 or more.

The setting on E-mail Alert is "if number of events drops by".

Is that drops by X exactly, or drops by at least X?

Tags (1)

Re: Alert if number of events drops by

Splunk Employee
Splunk Employee

The Answers answer to this Answers post is: "Basic conditional alerts trigger alert actions when set thresholds in the number of events, sources, or hosts in your results are exceeded.
i.e. "at least X"

View solution in original post