Hi guys,
i've a doubt regarding "activare alarm when" under Condition of activation in alarm editing window.
i add an img to explain better: (sorry for italian)
do you know how to find a reference guide on Splunk Docs? or have you any hint this?
Many thx
That field tells Splunk when to trigger the alert. The most common option, in my experience, is "number of results", but your choice will depend on the alert query. See http://docs.splunk.com/Documentation/Splunk/7.1.1/Alert/AlertTriggerConditions