Alerting

How can I get the matching events count into an alert message?

splunk_skuehne
Engager

Hello,

I created an alert, if a search brings up less than 1,000 results. How can I add the exact number of results to the alert message?
Currently the trigger is "Number of results" "is less than" 1,000. When I mark "Inline Table" I get all results in the mail, but not the count.

How can I get the count of all events into the alert mail?
Thank you!

0 Karma
1 Solution

s2_splunk
Splunk Employee
Splunk Employee

Take a look at the documentation here. $job.resultCount$ is what you are looking for, I think.

View solution in original post

elliotproebstel
Champion

In the email, you can reference the token $job.resultCount$, which will contain the number of results returned by the job.
For information about other tokens you can use in the email, here is the documentation:
https://docs.splunk.com/Documentation/SplunkCloud/6.6.3/Alert/EmailNotificationTokens

s2_splunk
Splunk Employee
Splunk Employee

Take a look at the documentation here. $job.resultCount$ is what you are looking for, I think.

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...