I have a search like below:
... | stats dc(cs_username) as unique_user
I want to run an hourly job and raise an alert when the unique_user number falls below 10 over last hour. How can I achieve this?
Thank you Pablo for pointing me to the right direction.
I ended up using below
.... | stats dc(cs_username) as unique_user | where unique_user < 10
and set an alert if the return result is greater > 0
Also used the cron job to run at 15th minute of every hour between 9 am to 6 pm during weekdays as per below . Hopefully should work.
15 09-18 * * 1-5
This will give you all the steps that you need to follow:-
http://docs.splunk.com/Documentation/Splunk/6.0.3/Alert/Definescheduledalerts
Run your search then click "Save As" and select "Alert". Fill in the form and click Save.