Splunk Search

Trick : alert even if no result

splunkreal
Motivator

Hello guys,

found out we can set up triggered alert if "greater than or equal to 0", had to use additional stats command to use custom condition  or use reports.

You just need to use "less than 10000" for instance (high number)

Hope this helps.

Thanks.

 

 

* If this helps, please upvote or accept solution if it solved *
Labels (1)
0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...