Alerting

custom trigger condition

meenu_2017
New Member

Qn on custom trigger condition for alerts.

Does the secondary search executes if the primary search returns no results?

0 Karma
1 Solution

woodcock
Esteemed Legend

Of course it does. The empty set is still a set and | where count==0 is a valid thing to use on such a set as a trigger. In any case, IMHO, best practice is to NEVER use the thresholding function; instead always code your thresholds in SPL and use number of events and is greater than 0.

View solution in original post

0 Karma

woodcock
Esteemed Legend

Of course it does. The empty set is still a set and | where count==0 is a valid thing to use on such a set as a trigger. In any case, IMHO, best practice is to NEVER use the thresholding function; instead always code your thresholds in SPL and use number of events and is greater than 0.

View solution in original post

0 Karma

niketnilay
Legend

@meenu_2017 what do you mean by primary search and secondary search? Please give example. If possible also what you are trying to achieve. Please mask/anonymize any sensitive information before posting code or data!

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

ss026381
Communicator

I think every filter after pipe only works on your primary search results. If you have 0 results for your primary search, it will just give you no result.

I am not 100% sure though.

0 Karma