Alerting

How to create an alert if count is greater than or less than a particular number?

vrmandadi
Builder

I am trying to create an alert based on stats count value...I want to alert if count is less than or greater than 500

Labels (1)
Tags (2)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

greater than or less than a particular number is the same as being not equal to that number. Is that what you want your alert triggered on?

0 Karma

vrmandadi
Builder

Yep.That is correct..So just use count!=500 ...is that the only thing needed

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Yes - you'll probably need a custom action and the result you are comparing must be in the first row of the search results

0 Karma

vrmandadi
Builder

Got it Thanks

0 Karma

PickleRick
SplunkTrust
SplunkTrust

If you're only interested in count, you can simply formulate your search so that it does the stats count part but if it's different than 500 returns no results. Then you would simply alert whenever you got any result from your search.

But of course if you're interested in detailed view of those 500 events it won't work.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...