Hi,
is there a way to suppress sending mails from scheduled searches if these are empty besides writing my own script.
Best Regards,
Konstantin
Use the alert condition "if number of events" > 1 in the Splunk UI.
You can also add the below condition to the savedsearch.conf as well:
quantity = 1
relation = greater than
Thanks