Alert Trigger Conditions

Alerts are triggered when the results of the search meet specific conditions. For example, you might have a condition that specifies to only alert when the count of results is greater than X. Triggering conditions are set when you set up the alert, and the following table lists the various conditions that are available:

Trigger condition

When is it triggered?

Per-result

Triggers whenever a search returns a result. It is only available for real-time alerts and leveraged by the per-result alert type.

Number of results

Triggers based on the number of search results. The options include greater than, less than, equal to, and not equal to.

Number of hosts

Triggers based on the number of hosts seen. ...

Get Splunk Operational Intelligence Cookbook - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.