Alerting

custom trigger condition

meenu_2017
Engager

Qn on custom trigger condition for alerts.

Does the secondary search executes if the primary search returns no results?

0 Karma
1 Solution

woodcock
Esteemed Legend

Of course it does. The empty set is still a set and | where count==0 is a valid thing to use on such a set as a trigger. In any case, IMHO, best practice is to NEVER use the thresholding function; instead always code your thresholds in SPL and use number of events and is greater than 0.

View solution in original post

0 Karma

woodcock
Esteemed Legend

Of course it does. The empty set is still a set and | where count==0 is a valid thing to use on such a set as a trigger. In any case, IMHO, best practice is to NEVER use the thresholding function; instead always code your thresholds in SPL and use number of events and is greater than 0.

0 Karma

niketn
Legend

@meenu_2017 what do you mean by primary search and secondary search? Please give example. If possible also what you are trying to achieve. Please mask/anonymize any sensitive information before posting code or data!

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

ss026381
Communicator

I think every filter after pipe only works on your primary search results. If you have 0 results for your primary search, it will just give you no result.

I am not 100% sure though.

0 Karma
Get Updates on the Splunk Community!

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...

Observability protocols to know about

Observability protocols define the specifications or formats for collecting, encoding, transporting, and ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...