Alerting

How to rerun the alert if the alert returns a result 0?

ydeveloper
New Member

If the alert returns a result 0 then I need to rerun the alert.
Can anybody please tell me how to do it?

0 Karma

drubench
Observer

I have a very similar question: is there a way to rerun alert until it gets the result of more than 0? 

0 Karma

tlam_splunk
Splunk Employee
Splunk Employee

you want to run the alert again and again until it got the result more than 0. Isn't it ?
Or alert return result 0 and just rerun the alert once only ?

0 Karma

Sukisen1981
Champion

well i think what you mean is your search for the alert does not return any results, that is different from zero. Is that the case?

0 Karma
Get Updates on the Splunk Community!

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...

Observability protocols to know about

Observability protocols define the specifications or formats for collecting, encoding, transporting, and ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...