Hi, can i configure from the "searches & reports" such that it trigger alert when the results=0 or i need to write a script to trigger such alert. If can configure from "searches & reports" how to go about configuring it. thks
Yes in trigger condition select number of results = 0.
If scripting it, same thing... Usually use something like len(), length(), count, word count (wc), etc to get the length of the results variable/object.
if len(results) == 0:
#do something
You can refer to the following Example of setting up alert. The example considers number of results greater than 5, you can set the same up for greater than 0. Trigger if number of results: is greater than 0
http://docs.splunk.com/Documentation/Splunk/latest/Alert/Alertexamples#Set_up_the_alert_2