Qn on custom trigger condition for alerts.
Does the secondary search executes if the primary search returns no results?
Of course it does. The empty set is still a set and | where count==0
is a valid thing to use on such a set as a trigger. In any case, IMHO, best practice is to NEVER use the thresholding function; instead always code your thresholds in SPL and use number of events
and is greater than 0
.
Of course it does. The empty set is still a set and | where count==0
is a valid thing to use on such a set as a trigger. In any case, IMHO, best practice is to NEVER use the thresholding function; instead always code your thresholds in SPL and use number of events
and is greater than 0
.
@meenu_2017 what do you mean by primary search and secondary search? Please give example. If possible also what you are trying to achieve. Please mask/anonymize any sensitive information before posting code or data!
I think every filter after pipe only works on your primary search results. If you have 0 results for your primary search, it will just give you no result.
I am not 100% sure though.