I am looking something like, If the alert trigger with query suppose- Index= abc sourcetype = ZXY "Error500" |stats count| where count >0 and suppose, I have a scheduled report name -- Error500 with below query Index= abc sourcetype = ZXY "Error500" |table _time, _raw so, if the alert trigger, then it should send out the report called Error500 ? is it possible ? any other solution please guide me. ----------------------------- the issue I am facing is, if use stats count it sending count only and with table it sending events logs. and I want if it trigger it should send event log. Thank you.
... View more