Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How to set up multiple conditions for our cron scheduled alert?

$
0
0
I have an alert scheduled to run on CRON. I wanted to trigger an alert when the number of results are less than X number with an attachment having the results. At the same time, I wanted to have the same alert to discard (not to include an attachment) if the number of results are less than or equal to ZERO (<=0). Do we have a way to have multiple conditions based on the number of alerts? I am aware of the custom condition, but trying to find a way to fit this scenario. Thanks Mathan J

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>