Alerting

Alert settings menu: What's the difference between "Per-Result" and "Number of Results" options?

ddrillic
Ultra Champion

What's the difference between alerts' Per-Result and the Number of Results options?

We are not clear about the difference between them.

alt text

When we set it up like this, we get alerts from August. Why is that?

alt text

Tags (2)
0 Karma
1 Solution

lfedak_splunk
Splunk Employee
Splunk Employee

Hey @ddrillic, It looks like the Number of Results triggers based on custom # of results.
Select Save As > Alert.
Specify the following values for the fields in the Save As Alert dialog box.

    Title: Errors in the last 24 hours
    Alert type: Scheduled
    Time Range: Run every day
    Schedule: At 10:00
    Trigger condition: Number of Results
    Trigger when number of results: is greater than 5.

Select the Send Email alert action.
Set the following email settings, using tokens in the Subject and Message fields.

    To: email recipient
    Priority: Normal
    Subject: Too many errors alert: $name$
    Message: There were $job.resultCount$ errors reported on $trigger_date$.
    Include: Link to Alert and Link to Results

And per-result triggers every time there is a search result, although you can specify a time period and optional field values for suppression.

View solution in original post

0 Karma

ddrillic
Ultra Champion

About the alerts from August. Maybe they got stuck in the Unix mail queues - how do we clear them, if that's the case?

0 Karma

lfedak_splunk
Splunk Employee
Splunk Employee

Hey @ddrillic, It looks like the Number of Results triggers based on custom # of results.
Select Save As > Alert.
Specify the following values for the fields in the Save As Alert dialog box.

    Title: Errors in the last 24 hours
    Alert type: Scheduled
    Time Range: Run every day
    Schedule: At 10:00
    Trigger condition: Number of Results
    Trigger when number of results: is greater than 5.

Select the Send Email alert action.
Set the following email settings, using tokens in the Subject and Message fields.

    To: email recipient
    Priority: Normal
    Subject: Too many errors alert: $name$
    Message: There were $job.resultCount$ errors reported on $trigger_date$.
    Include: Link to Alert and Link to Results

And per-result triggers every time there is a search result, although you can specify a time period and optional field values for suppression.

0 Karma

ddrillic
Ultra Champion

Thank you @lfedak!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Cisco Data Fabric from Architecture to Investigation, Better SOC Visibility, and More ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

The Trust Gap: Why a Data Foundation is Fundamental to an Agentic Enterprise

The Trust Gap: Why a data foundation is fundamental to an  Agentic Enterprise.   Agentic AI is transforming ...

Data Management Digest – September 2026

    Welcome to the September 2026 edition of Data Management Digest! September brought a fresh wave of ...