Splunk Search

Alert on table with custom email subject field value

rmiller3
Engager

I got an alert working "for each result" by using a query that creates the following table:

errorType             count

Client                  10
Credentials      50
Unknown             5

How do I set a different threshold for each result?

I tried using a custom trigger as follows and was hoping to only get an email for "client" and "credentials", but I still get all 3.

 

search (errorType = "Client" AND count > 8 ) OR (errorType = "Credentials" AND count > 8 ) OR (errorType = "Other" AND count >8 )

 

 

 

Labels (1)
0 Karma
1 Solution

marnall
Motivator

That should work already. Could you try putting that search filter at the end of your alert search?

<yoursearch>
| search (errorType = "Client" AND count > 8 ) OR (errorType = "Credentials" AND count > 8 ) OR (errorType = "Other" AND count > 8 )

 

View solution in original post

0 Karma

rmiller3
Engager

That works.  I was really trying to have a custom alert message with just the thresholds (since my query categorizes different error types and is fairly long, I was hoping not to put it in the alert email). 

However, I think putting the whole query is fine at the end of the day, thanks!

0 Karma

marnall
Motivator

That should work already. Could you try putting that search filter at the end of your alert search?

<yoursearch>
| search (errorType = "Client" AND count > 8 ) OR (errorType = "Credentials" AND count > 8 ) OR (errorType = "Other" AND count > 8 )

 

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...