I made a savedsearch with a simple search in it.
As a condition I selected
"if number of events"
"is greater than"
with the value "0"
although no events are selected the alert is triggered and an email is set.
Does anyone else also have this problem? There is a workaround to use "if condition is met" but it doesn't seem logical to me that the option "if number of events" doesn't work properly.
@rrovers Can you check this https://community.splunk.com/t5/Alerting/Why-is-my-savedsearches-conf-configuration-not-honoring-the...
@kiran_panchavat , thanks but it's still not clear to me.
Do you mean this sentence in the solution you gave ?
"Alerts are triggered if the specified search yields a non-empty search result list."
It still looks like a bug to me or at least it's very unclear.