Dear Experts: I'm new to Splunk. I have a search output device lists with events number greater than 20 as a report, for example, event_date src events 2021-02-08 device1 102 2021-02-08 device2 20 I need to have a new search to look into the event details on each of the device on the list to create final report and alerts if applicable. The report has to be dynamic as part of my search each time as scheduled task hourly, cannot be a static csv file as Lookup. Please advise strategies and code. Thank you. Lisa
... View more