Alerting

Alert settings menu: What's the difference between "Per-Result" and "Number of Results" options?

ddrillic
Ultra Champion

What's the difference between alerts' Per-Result and the Number of Results options?

We are not clear about the difference between them.

alt text

When we set it up like this, we get alerts from August. Why is that?

alt text

Tags (2)
0 Karma
1 Solution

lfedak_splunk
Splunk Employee
Splunk Employee

Hey @ddrillic, It looks like the Number of Results triggers based on custom # of results.
Select Save As > Alert.
Specify the following values for the fields in the Save As Alert dialog box.

    Title: Errors in the last 24 hours
    Alert type: Scheduled
    Time Range: Run every day
    Schedule: At 10:00
    Trigger condition: Number of Results
    Trigger when number of results: is greater than 5.

Select the Send Email alert action.
Set the following email settings, using tokens in the Subject and Message fields.

    To: email recipient
    Priority: Normal
    Subject: Too many errors alert: $name$
    Message: There were $job.resultCount$ errors reported on $trigger_date$.
    Include: Link to Alert and Link to Results

And per-result triggers every time there is a search result, although you can specify a time period and optional field values for suppression.

View solution in original post

0 Karma

ddrillic
Ultra Champion

About the alerts from August. Maybe they got stuck in the Unix mail queues - how do we clear them, if that's the case?

0 Karma

lfedak_splunk
Splunk Employee
Splunk Employee

Hey @ddrillic, It looks like the Number of Results triggers based on custom # of results.
Select Save As > Alert.
Specify the following values for the fields in the Save As Alert dialog box.

    Title: Errors in the last 24 hours
    Alert type: Scheduled
    Time Range: Run every day
    Schedule: At 10:00
    Trigger condition: Number of Results
    Trigger when number of results: is greater than 5.

Select the Send Email alert action.
Set the following email settings, using tokens in the Subject and Message fields.

    To: email recipient
    Priority: Normal
    Subject: Too many errors alert: $name$
    Message: There were $job.resultCount$ errors reported on $trigger_date$.
    Include: Link to Alert and Link to Results

And per-result triggers every time there is a search result, although you can specify a time period and optional field values for suppression.

0 Karma

ddrillic
Ultra Champion

Thank you @lfedak!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...