Hi Splunk,
I am in trying to create an alert that will send email to users if the search query returned results if there is 10 unique repository returned in the events.
search_query earliest=-10m@m latest=now
| stats count by repository| where count > 9 | sort - count
Currently, the alert trigger if there is an occurence of 10 times of the SAME repository. I want to improve the query by triggering alert if only there is 10 DIFFERENT repository.
You could use stats dc(repository)
and trigger when that is 10 or more, or stick to stats count by repository
and set the alert trigger to only trigger if the result count is 10 or more.