We have some users asking for Notable Events and emails depending on search results.
Example...If the number of errors returned the last 5 minutes is < 5, send an email. If > 5 allow notable event to be generated.
I don't want to create 2 searches for this (alert and correlation search). Is it possible to write 1 search to accomplish this?
I don't think its possible with default Splunk alert action behavior.