We would need more information, in order to give you proper help here. Could you post your alert search (mask anything sensitive, its schedule information, the time range it works on (Start time and End time) etc?
You can split it up into 2 searches that run one right after. The second one writes the results to a file with | outputcsv
. The first one reads this file with inputcsv
and compares the results in this file (the previous day's run) with the results from your existing search. If it is the same, make sure that your combined search generates 0 rows and have your alert email only when Number of events is greater than 0
. Done.