Alerting

email alert not sending when the condition is ""Number of Results is = 0"

alexchandb
Engager

I am having trouble with getting a email triggered for the following condition.
"Number of Results is = 0"
the search query is as follows.

index="xxxxx" sourcetype="syslog" earliest=-1d latest=now | stats count

the result of the search is :
count = 0 .

It is able to send other alerts.

0 Karma

woodcock
Esteemed Legend

You have to set Trigger alert when = Custom and the condition box below this to be count = 0. The other setting counts the number of rows returned which in your case will always be 1 (not 0 the way that you were thinking).

0 Karma

inventsekar
SplunkTrust
SplunkTrust

while reading the post, all looks fine..

  • maybe, verify the mail address.
  • try adding this adding one more action - "Add to Triggered Alerts", so that you will know the alert got triggered or not.
  • maybe, verify the Alert Schedule.
  • It is able to send other alerts. // you mean, other email alerts are working fine?
thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
Get Updates on the Splunk Community!

Splunk Observability Cloud's AI Assistant in Action Series: Auditing Compliance and ...

This is the third post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...