I have a below query where i search two text field and see how many time each occurred and find the difference. ("SSO Initiated" OR "SSO Completed") | stats count(eval(searchmatch("SSO Initiated"))) as SSO_Initiated count(eval(searchmatch("SSO Completed"))) as SSO_Completed | eval Difference=SSO_Initiated-SSO_Completed I want to create alert if Difference > 20, then mail needs to be sent. This check should keep happening every 15 minute and check in last 15 minute if Difference > 20, then trigger mail.
... View more