Alerting

How to create an alert if count is greater than or less than a particular number?

vrmandadi
Builder

I am trying to create an alert based on stats count value...I want to alert if count is less than or greater than 500

Labels (1)
Tags (2)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

greater than or less than a particular number is the same as being not equal to that number. Is that what you want your alert triggered on?

0 Karma

vrmandadi
Builder

Yep.That is correct..So just use count!=500 ...is that the only thing needed

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Yes - you'll probably need a custom action and the result you are comparing must be in the first row of the search results

0 Karma

vrmandadi
Builder

Got it Thanks

0 Karma

PickleRick
SplunkTrust
SplunkTrust

If you're only interested in count, you can simply formulate your search so that it does the stats count part but if it's different than 500 returns no results. Then you would simply alert whenever you got any result from your search.

But of course if you're interested in detailed view of those 500 events it won't work.

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...