I am using splunk to aggregate events from an estate of endpoints. I have notifications in place for known issues and problems based upon the event type. However, I have a need to be notified when any event starts to be reported that has not previously been reported in volume. Any suggestions?