Hi,
I have an alert that is supposed to trigger an email each subsequent day when there are 0 logs in the last 24 hours against a particular search.
However, when there ARE 0 logs in the past 24 hours, my alert does not get triggered for some reason.
My alert is as follows:
Can you please help as I do not understand why this alert is not working as expected?
Many thanks!
Please share the search itself.
The search is as follows::
index="corp_security" sourcetype="dns_rpz"
The alert should send an email per day for every subsequent day when there are 0 logs in the last 24 hours
https://docs.splunk.com/Documentation/Splunk/9.0.3/Alert/AlertTriggerConditions
See the last example
So I need to add “earliest=0 latest=now | stats count” to mr current query? Would that look at just the data for the last 24 hours though?