email alert not sending when the condition is ""Number of Results is = 0"


I am having trouble with getting a email triggered for the following condition.
"Number of Results is = 0"
the search query is as follows.

index="xxxxx" sourcetype="syslog" earliest=-1d latest=now | stats count

the result of the search is :
count = 0 .

It is able to send other alerts.

0 Karma

Esteemed Legend

You have to set Trigger alert when = Custom and the condition box below this to be count = 0. The other setting counts the number of rows returned which in your case will always be 1 (not 0 the way that you were thinking).

0 Karma


while reading the post, all looks fine..

  • maybe, verify the mail address.
  • try adding this adding one more action - "Add to Triggered Alerts", so that you will know the alert got triggered or not.
  • maybe, verify the Alert Schedule.
  • It is able to send other alerts. // you mean, other email alerts are working fine?
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...