Alerting

Token for count of suppressed results

techspec
Explorer

I have an alert that runs every hour, triggered when the number of results is greater than 0, for reach result. 

I have the throttle option checked, and "suppress results containing field value" set to "myData.message" (this is an error message I want alerts for).

The action is a Slack message.

The result of this alert is one Slack message for each unique error message found in the past hour.

I want to know if there's a way to get the count of the specific/unique error message that it's firing for.

$job.resultCount$ gives me the count of all error messages found, so that doesn't work for my use case.

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...