I'm attempting to build a scheduled search based on certain aggregate values, something like the following:
"Specific Search Criteria" | *filter based on environment* | parse "FooId:* " as _foo | count(_foo) by _foo | sort _count | where _count > *some_threshold*
This query works great for viewing a list of Foo's which have occurred more than X times in the search window, which ends up being accessible via the $AggregateResultsJson variable. I can fire this off via the Webhook to Slack just fine, the problem is that I want to trigger it only when the count of $AggregateResultsJson is say, non zero... and even be able to display that value in the Slack message.
$NumRawResults contains the number of messages processed prior to my filtering, but there seems to be nothing like a $NumAggregateResults.
Is there another way that I am missing?
Please sign in to leave a comment.