Alerting

Alert settings menu: What's the difference between "Per-Result" and "Number of Results" options?

ddrillic
Ultra Champion

What's the difference between alerts' Per-Result and the Number of Results options?

We are not clear about the difference between them.

alt text

When we set it up like this, we get alerts from August. Why is that?

alt text

Tags (2)
0 Karma
1 Solution

lfedak_splunk
Splunk Employee
Splunk Employee

Hey @ddrillic, It looks like the Number of Results triggers based on custom # of results.
Select Save As > Alert.
Specify the following values for the fields in the Save As Alert dialog box.

    Title: Errors in the last 24 hours
    Alert type: Scheduled
    Time Range: Run every day
    Schedule: At 10:00
    Trigger condition: Number of Results
    Trigger when number of results: is greater than 5.

Select the Send Email alert action.
Set the following email settings, using tokens in the Subject and Message fields.

    To: email recipient
    Priority: Normal
    Subject: Too many errors alert: $name$
    Message: There were $job.resultCount$ errors reported on $trigger_date$.
    Include: Link to Alert and Link to Results

And per-result triggers every time there is a search result, although you can specify a time period and optional field values for suppression.

View solution in original post

0 Karma

ddrillic
Ultra Champion

About the alerts from August. Maybe they got stuck in the Unix mail queues - how do we clear them, if that's the case?

0 Karma

lfedak_splunk
Splunk Employee
Splunk Employee

Hey @ddrillic, It looks like the Number of Results triggers based on custom # of results.
Select Save As > Alert.
Specify the following values for the fields in the Save As Alert dialog box.

    Title: Errors in the last 24 hours
    Alert type: Scheduled
    Time Range: Run every day
    Schedule: At 10:00
    Trigger condition: Number of Results
    Trigger when number of results: is greater than 5.

Select the Send Email alert action.
Set the following email settings, using tokens in the Subject and Message fields.

    To: email recipient
    Priority: Normal
    Subject: Too many errors alert: $name$
    Message: There were $job.resultCount$ errors reported on $trigger_date$.
    Include: Link to Alert and Link to Results

And per-result triggers every time there is a search result, although you can specify a time period and optional field values for suppression.

0 Karma

ddrillic
Ultra Champion

Thank you @lfedak!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...