Hey all,
I have two searches that both run independently of one another. They both work fine by themselves. Now, I would like the run the second search, if and only if, the first search does NOT return any results. I'm trying to do something like this right now:
<first search> | stats count | where count=0 | <second search>
But that doesn't quite work, the events from
If you schedule the first search, you could schedule a second search which looks for result_count=0 in the internal log:
index=_internal startminutesago=5 sourcetype=scheduler savedsearch_name="name_of_first_scheduled_search" status=success result_count=0 | append [ search "second search query" ]
I apologize, thanks for catching that. I've edited my question.
What if there are no results from first search? In that case you want your second search to be executed or not executed?
You have contradicting statements in your question.
"Now, I would like the run the second search, if and only if, the first search doesn't return any results."
"What I'd like is for the events from