I am trying to create an alert based on stats count value...I want to alert if count is less than or greater than 500
greater than or less than a particular number is the same as being not equal to that number. Is that what you want your alert triggered on?
Yep.That is correct..So just use count!=500 ...is that the only thing needed
Yes - you'll probably need a custom action and the result you are comparing must be in the first row of the search results
Got it Thanks
If you're only interested in count, you can simply formulate your search so that it does the stats count part but if it's different than 500 returns no results. Then you would simply alert whenever you got any result from your search.
But of course if you're interested in detailed view of those 500 events it won't work.