Hi ,
I am using the below query to send an email alert when the count of the string "process started" appears to be 0 . But the alert is not getting triggered on the below condition , Is the below query correct ?
index=abc "process started" |stats count by host|where count = 0
The reason is, the base query itself is empty.
Please try something like
index=abc "process started" |stats count by host
| appendpipe [ stats count | where count=0 | eval host="EMPTY" ]
| search host=EMPTY
.. and then trigger based if host=EMPTY