Alerting

How can I get the matching events count into an alert message?

splunk_skuehne
Engager

Hello,

I created an alert, if a search brings up less than 1,000 results. How can I add the exact number of results to the alert message?
Currently the trigger is "Number of results" "is less than" 1,000. When I mark "Inline Table" I get all results in the mail, but not the count.

How can I get the count of all events into the alert mail?
Thank you!

0 Karma
1 Solution

s2_splunk
Splunk Employee
Splunk Employee

Take a look at the documentation here. $job.resultCount$ is what you are looking for, I think.

View solution in original post

elliotproebstel
Champion

In the email, you can reference the token $job.resultCount$, which will contain the number of results returned by the job.
For information about other tokens you can use in the email, here is the documentation:
https://docs.splunk.com/Documentation/SplunkCloud/6.6.3/Alert/EmailNotificationTokens

s2_splunk
Splunk Employee
Splunk Employee

Take a look at the documentation here. $job.resultCount$ is what you are looking for, I think.

Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...