Hi basically you should/could combine those event with bin or eventstats, based on your requirements (fixed or sliding span). Here is one old answer for this https://community.splunk.com/t5/Alerting/how-to-generate-alert-based-on-the-count-of-unique-filed-value/m-p/329520 and you could found more quite easily. r. Ismo
... View more