Thanks Giuseppe. Yes well noted on the real-time, have changed it accordingly. Regarding "Number of Results" (as applied in Rela-time searches) have tested a bit deeper into the behaviour with a high frequency log stream (one per second, is a protocol timetick) and found the following: 1. The key is the rolling window concept in the Real-time search. The window shifts and is not a discrete timeframe excluding previous matched events. 2. The way I had it setup it created an email every 5 seconds, with the last ~300 events in the mail. Eg. Saved Search [SPLUNK ALERT - P3 - ESPMCASTPROBE B FEED]: number of events (299) 3. Received a mail once for each result that there were more than 10 events per search, which triggered every 5 seconds (12 per minute). Having it now as a Scheduled search provides the result needed, ie. 1. Looking at the last 5 minutes 2. Evaluating if it has more than 10 events 3. Triggering the event accordingly 4. Scheduled search again for 5 mins ahead ("sleeping" for 5 mins) many thanks
... View more