Splunk Search

Alert is triggered while condition "if number of events is greater than 0" not met

rrovers
Contributor

I made a savedsearch with a simple search in it. 

As a condition I selected 

"if number of events"

"is greater than"

with the value "0"

although no events are selected the alert is triggered and an email is set.

Does anyone else also have this problem?  There is a workaround to use "if condition is met" but it doesn't seem logical to me that the option "if number of events" doesn't work properly.

0 Karma

kiran_panchavat
SplunkTrust
SplunkTrust

@rrovers Can you check this https://community.splunk.com/t5/Alerting/Why-is-my-savedsearches-conf-configuration-not-honoring-the... 

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma

rrovers
Contributor

@kiran_panchavat , thanks but it's still not clear to me.

Do you mean this sentence in the solution you gave ?

"Alerts are triggered if the specified search yields a non-empty search result list."

  It still looks like a bug to me or at least it's  very unclear.

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...