Alerting
Highlighted

How to trigger alert when one row of list equals to zero

Explorer

Hi Experts,

I have a search query that give me a result table like below:

EmployeeSalary
A1000
B2000
C0

 

How can we trigger an alert when one of our employee's salary equals to zero or specific number?

Labels (3)
0 Karma
Highlighted

Re: How to trigger alert when one row of list equals to zero

Legend

Hi @thinhdinh ,

you have to add a condition at the end of your search, e.g.

 

0 Karma
Highlighted

Re: How to trigger alert when one row of list equals to zero

Legend

Sorry: wrong click!

you have to add a condition at the end of your search, e.g.:

| where Salary=0

and run an alert triggered when you have results.

Ciao.

Giuseppe

View solution in original post

Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.