hi
what is the syntax of the custom condition search
I have a search like
earliest=-5m heartbeat | stats count
I want it to run a script when count=0
I tried "if custom condition is met" then for value I put "|where count=0"
but the alert triggered even though count was one
I can't find the documentatino about "if custom condition is met" otherwise I would have looked there
thanks,
Set up your alert like this:
[your alert]
...
alert_condition = where count=0
counttype = custom
...
search = earliest=-5m heartbeat | stats count