Splunk Search

Alert is triggered while condition "if number of events is greater than 0" not met

rrovers
Contributor

I made a savedsearch with a simple search in it. 

As a condition I selected 

"if number of events"

"is greater than"

with the value "0"

although no events are selected the alert is triggered and an email is set.

Does anyone else also have this problem?  There is a workaround to use "if condition is met" but it doesn't seem logical to me that the option "if number of events" doesn't work properly.

0 Karma

kiran_panchavat
SplunkTrust
SplunkTrust

@rrovers Can you check this https://community.splunk.com/t5/Alerting/Why-is-my-savedsearches-conf-configuration-not-honoring-the... 

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma

rrovers
Contributor

@kiran_panchavat , thanks but it's still not clear to me.

Do you mean this sentence in the solution you gave ?

"Alerts are triggered if the specified search yields a non-empty search result list."

  It still looks like a bug to me or at least it's  very unclear.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...