Alerting

Alert settings menu: What's the difference between "Per-Result" and "Number of Results" options?

ddrillic
Ultra Champion

What's the difference between alerts' Per-Result and the Number of Results options?

We are not clear about the difference between them.

alt text

When we set it up like this, we get alerts from August. Why is that?

alt text

Tags (2)
0 Karma
1 Solution

lfedak_splunk
Splunk Employee
Splunk Employee

Hey @ddrillic, It looks like the Number of Results triggers based on custom # of results.
Select Save As > Alert.
Specify the following values for the fields in the Save As Alert dialog box.

    Title: Errors in the last 24 hours
    Alert type: Scheduled
    Time Range: Run every day
    Schedule: At 10:00
    Trigger condition: Number of Results
    Trigger when number of results: is greater than 5.

Select the Send Email alert action.
Set the following email settings, using tokens in the Subject and Message fields.

    To: email recipient
    Priority: Normal
    Subject: Too many errors alert: $name$
    Message: There were $job.resultCount$ errors reported on $trigger_date$.
    Include: Link to Alert and Link to Results

And per-result triggers every time there is a search result, although you can specify a time period and optional field values for suppression.

View solution in original post

0 Karma

ddrillic
Ultra Champion

About the alerts from August. Maybe they got stuck in the Unix mail queues - how do we clear them, if that's the case?

0 Karma

lfedak_splunk
Splunk Employee
Splunk Employee

Hey @ddrillic, It looks like the Number of Results triggers based on custom # of results.
Select Save As > Alert.
Specify the following values for the fields in the Save As Alert dialog box.

    Title: Errors in the last 24 hours
    Alert type: Scheduled
    Time Range: Run every day
    Schedule: At 10:00
    Trigger condition: Number of Results
    Trigger when number of results: is greater than 5.

Select the Send Email alert action.
Set the following email settings, using tokens in the Subject and Message fields.

    To: email recipient
    Priority: Normal
    Subject: Too many errors alert: $name$
    Message: There were $job.resultCount$ errors reported on $trigger_date$.
    Include: Link to Alert and Link to Results

And per-result triggers every time there is a search result, although you can specify a time period and optional field values for suppression.

0 Karma

ddrillic
Ultra Champion

Thank you @lfedak!

0 Karma
Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...