I have the splunk alert scheduled to run every 5 min to trigger an email to report if any splunk search peer hosts are down.
| rest splunk_server=local / services/search/distributed/peers/
| where status!="Up" AND disabled=0
| fields peerName, status | rename peerName as Instance, status as Status
I want the alert to trigger to send an email only when the same hosts fails more than once as there seems many false positive.
How to achieve this?
This is a similar case and maybe useful for you.