IMHO, you should only use the alert trigger combination of number of results and is greater than 0 and keep the threshold condition inside SPL. That way it is inherently obvious to any investigator exactly how/what triggered. In this design, yes, the variable to examine must exist in the search results. If the threshold is also a field name, then you must use | where . If you are hard-coding a value, you can use either | search or | where .
... View more