I tried the following,
sourcetype="cisco:*" [|inputlookup Testlist.csv | fields scr_ip | rename scr_ip AS dest_ip] | stats count by src_ip | sort desc - count
Hi Look at the following link
https://answers.splunk.com/answers/365849/how-to-set-the-search-result-as-an-email-alert.html#answer...