Alerting

How to create an Alert when the system gives 0 results?

rashi83
Path Finder

Hi,

Need to create a Alert where if Search produces zero results then alert should be send , this should be checked every 15 mins. Is there any internal log file on which this alert can be created so that it doesn't create overhead on the system.

Tags (2)
0 Karma

jaime_ramirez
Communicator

Hi

You can check the results given by an alert with the following:

index=_internal sourcetype="scheduler" search_type=scheduled savedsearch_name="Your alert name"
| where result_count=0

Hope it helps.

Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...