Alerting

Alert settings menu: What's the difference between "Per-Result" and "Number of Results" options?

ddrillic
Ultra Champion

What's the difference between alerts' Per-Result and the Number of Results options?

We are not clear about the difference between them.

alt text

When we set it up like this, we get alerts from August. Why is that?

alt text

Tags (2)
0 Karma
1 Solution

lfedak_splunk
Splunk Employee
Splunk Employee

Hey @ddrillic, It looks like the Number of Results triggers based on custom # of results.
Select Save As > Alert.
Specify the following values for the fields in the Save As Alert dialog box.

    Title: Errors in the last 24 hours
    Alert type: Scheduled
    Time Range: Run every day
    Schedule: At 10:00
    Trigger condition: Number of Results
    Trigger when number of results: is greater than 5.

Select the Send Email alert action.
Set the following email settings, using tokens in the Subject and Message fields.

    To: email recipient
    Priority: Normal
    Subject: Too many errors alert: $name$
    Message: There were $job.resultCount$ errors reported on $trigger_date$.
    Include: Link to Alert and Link to Results

And per-result triggers every time there is a search result, although you can specify a time period and optional field values for suppression.

View solution in original post

0 Karma

ddrillic
Ultra Champion

About the alerts from August. Maybe they got stuck in the Unix mail queues - how do we clear them, if that's the case?

0 Karma

lfedak_splunk
Splunk Employee
Splunk Employee

Hey @ddrillic, It looks like the Number of Results triggers based on custom # of results.
Select Save As > Alert.
Specify the following values for the fields in the Save As Alert dialog box.

    Title: Errors in the last 24 hours
    Alert type: Scheduled
    Time Range: Run every day
    Schedule: At 10:00
    Trigger condition: Number of Results
    Trigger when number of results: is greater than 5.

Select the Send Email alert action.
Set the following email settings, using tokens in the Subject and Message fields.

    To: email recipient
    Priority: Normal
    Subject: Too many errors alert: $name$
    Message: There were $job.resultCount$ errors reported on $trigger_date$.
    Include: Link to Alert and Link to Results

And per-result triggers every time there is a search result, although you can specify a time period and optional field values for suppression.

0 Karma

ddrillic
Ultra Champion

Thank you @lfedak!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Self-Healing Pipeline Is Now Generally Available: AI-Powered CIM Compliance

Maintaining data integrity across security and analytics pipelines is an ongoing challenge. Data ...