Hi,
We are using the Splunk Pagerduty integration to page out for certain alerts. The integration works fine the search returns some events. For example: if we are alerting if a search returns more than 1 event, we get the splunk email and the PD alerts out. If we set an alert for if less than 1 event is returned, we get the splunk email but PD doesn't trigger. When working with PD support, they the search result can't be "no results". I also tried adding "| append [| search | fields - * | eval count=0]" to my search so I would get a blank event instead but PD still didn't trigger.
Anyone have any suggestions were I can get an event with a bunch of zero's instead of blank or no results?
Thanks
Are you creating these alerts in Splunk core or enterprise security? we had a similar issue with ES. They had to build custom integration on their end(pager duty)...