I'm configuring this whole thing simply for sending buckets to S3 as soon as they are eligible (which is warm status).
I'm still confused with search and alert settings. Number of results > 1 should be for which period of time?
And another option, is it "once" or "for each result"? And if "for each result", what should be field value for throttling results, which splunk requires to be set in this case.
... View more