Hi
Currently, My scheduled alert runs every five minutes but I need to get it triggered when the event count goes more than 2 in a minute. What is the best way to handle it?
Hi
basically you should/could combine those event with bin or eventstats, based on your requirements (fixed or sliding span).
Here is one old answer for this https://community.splunk.com/t5/Alerting/how-to-generate-alert-based-on-the-count-of-unique-filed-va... and you could found more quite easily.
r. Ismo