<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Alerting: customized conditions, memory is above a threshold for two times in a row for a specific server in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Alerting-customized-conditions-memory-is-above-a-threshold-for/m-p/465377#M12853</link>
    <description>&lt;P&gt;Hello,&lt;BR /&gt;
I have the next query in an alert to check the status of 6 hosts:&lt;BR /&gt;
index=idx_nmon_data  sourcetype=Perfmon:Memory eventtype=perfmon_memory&lt;BR /&gt;
| eval threshold=95&lt;BR /&gt;
| where mem_used &amp;gt; threshold&lt;BR /&gt;
| table _time host mem_used threshold&lt;/P&gt;

&lt;P&gt;I would like that the alert is triggered when for two times in a row a specific server is above 95% of mem_used. &lt;/P&gt;

&lt;P&gt;And that in the email appears the next fields: _time     host       mem_used      threshold&lt;BR /&gt;
I thought about  two options but they dont match exactly what I want:&lt;BR /&gt;
              -  Do a: stats dc(_time) as times by host (in the search) and configure alert triggered when results are &amp;gt;1&lt;BR /&gt;
                   &amp;gt;&amp;gt;&amp;gt;but in this case i lose information in the email of mem_used and _time, and I would like to see them in the table of the email&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;          - Inside the alert, as customized condition, to write: search dc(_time) by host &amp;gt; 1, but it does not work
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Anyone has othe ideas? or am i doing something wrong?&lt;/P&gt;

&lt;P&gt;I would like to maintain as well this is an only one query just to avoid consume the ressources of my search head server&lt;/P&gt;

&lt;P&gt;Thanks in advance&lt;BR /&gt;
Jaime&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2020 04:51:13 GMT</pubDate>
    <dc:creator>jaimelopez</dc:creator>
    <dc:date>2020-09-30T04:51:13Z</dc:date>
    <item>
      <title>Alerting: customized conditions, memory is above a threshold for two times in a row for a specific server</title>
      <link>https://community.splunk.com/t5/Alerting/Alerting-customized-conditions-memory-is-above-a-threshold-for/m-p/465377#M12853</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;
I have the next query in an alert to check the status of 6 hosts:&lt;BR /&gt;
index=idx_nmon_data  sourcetype=Perfmon:Memory eventtype=perfmon_memory&lt;BR /&gt;
| eval threshold=95&lt;BR /&gt;
| where mem_used &amp;gt; threshold&lt;BR /&gt;
| table _time host mem_used threshold&lt;/P&gt;

&lt;P&gt;I would like that the alert is triggered when for two times in a row a specific server is above 95% of mem_used. &lt;/P&gt;

&lt;P&gt;And that in the email appears the next fields: _time     host       mem_used      threshold&lt;BR /&gt;
I thought about  two options but they dont match exactly what I want:&lt;BR /&gt;
              -  Do a: stats dc(_time) as times by host (in the search) and configure alert triggered when results are &amp;gt;1&lt;BR /&gt;
                   &amp;gt;&amp;gt;&amp;gt;but in this case i lose information in the email of mem_used and _time, and I would like to see them in the table of the email&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;          - Inside the alert, as customized condition, to write: search dc(_time) by host &amp;gt; 1, but it does not work
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Anyone has othe ideas? or am i doing something wrong?&lt;/P&gt;

&lt;P&gt;I would like to maintain as well this is an only one query just to avoid consume the ressources of my search head server&lt;/P&gt;

&lt;P&gt;Thanks in advance&lt;BR /&gt;
Jaime&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:51:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alerting-customized-conditions-memory-is-above-a-threshold-for/m-p/465377#M12853</guid>
      <dc:creator>jaimelopez</dc:creator>
      <dc:date>2020-09-30T04:51:13Z</dc:date>
    </item>
  </channel>
</rss>

