Alerting

Custom Condition Alert if total increases

yechoorv
Explorer

Hello,

I need to set an alert on a scheduled search when the Total of the rows increases and need help making the custom condition. I tried doing "if number of events rises by 1" but it didn't seem to work.

I was thinking something along the lines of:

search Total rises by 1

0 Karma

splunker12er
Motivator

Trigger alert conditions , works like below,
'Number of events' is equal to | greater than| lesser than|

Say if you give the values as greater than '0' , if your search query returns ,

0 result - it will not trigger alert
1 result - it will trigger alert

0 Karma

splunker12er
Motivator
0 Karma

yechoorv
Explorer

I need to use the 'rises by' function though.

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.0.2 Availability: On cloud and On-premise!

A few months ago, we released Splunk Enterprise Security 8.0 for our cloud customers. Today, we are excited to ...

Logs to Metrics

Logs and Metrics Logs are generally unstructured text or structured events emitted by applications and written ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...