I already have an alert setup if a user does not have activity. The alert is set with number of results = 0. However, we have situation when splunk forwarder did not send data because the underlying logs stopped populating. This created a false negative that user is not logging. How do I incorporate the scenario that if no logs are coming than no alert.
The current search as follows.
index=appl_index user="xyz"
I would check
index=appl_index | stats count | if (count=0,do not alert, else go with my current query)
Thanks in advance.
@gnshah12345,
Try this. You may adjust the last condition according to your requirement.
index=appl_index |stats count(eval(user="xyz")) as userCount,count as total|where userCount>0 OR total < 1