Splunk Search

Alert is triggered while condition "if number of events is greater than 0" not met

rrovers
Contributor

I made a savedsearch with a simple search in it. 

As a condition I selected 

"if number of events"

"is greater than"

with the value "0"

although no events are selected the alert is triggered and an email is set.

Does anyone else also have this problem?  There is a workaround to use "if condition is met" but it doesn't seem logical to me that the option "if number of events" doesn't work properly.

0 Karma

kiran_panchavat
Champion

@rrovers Can you check this https://community.splunk.com/t5/Alerting/Why-is-my-savedsearches-conf-configuration-not-honoring-the... 

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma

rrovers
Contributor

@kiran_panchavat , thanks but it's still not clear to me.

Do you mean this sentence in the solution you gave ?

"Alerts are triggered if the specified search yields a non-empty search result list."

  It still looks like a bug to me or at least it's  very unclear.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...