Splunk Search

Alert is triggered while condition "if number of events is greater than 0" not met

rrovers
Contributor

I made a savedsearch with a simple search in it. 

As a condition I selected 

"if number of events"

"is greater than"

with the value "0"

although no events are selected the alert is triggered and an email is set.

Does anyone else also have this problem?  There is a workaround to use "if condition is met" but it doesn't seem logical to me that the option "if number of events" doesn't work properly.

0 Karma

kiran_panchavat
SplunkTrust
SplunkTrust

@rrovers Can you check this https://community.splunk.com/t5/Alerting/Why-is-my-savedsearches-conf-configuration-not-honoring-the... 

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma

rrovers
Contributor

@kiran_panchavat , thanks but it's still not clear to me.

Do you mean this sentence in the solution you gave ?

"Alerts are triggered if the specified search yields a non-empty search result list."

  It still looks like a bug to me or at least it's  very unclear.

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...