As mentioned, save the search as an alert and the threshold would by <1 stats returned would trigger the alert. A word of caution about monitoring for negatives or low thresholds. If your data pipelines get backed up, scheduled searches looking for negatives will see little or no data for your search at search time due to a slow pipeline. This can make you crazy since the pipelines will catch up and you'll be left wondering why splunk is "fibbing" to you. The truth is at that moment the scheduled search ran, the alert was valid from the search's perspective but looking at it after the fact, all the data will have been filled in. Caveat emptor
... View more