<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Setting an alert for consecutive &amp;quot;errors&amp;quot; sorted by another variable in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Setting-an-alert-for-consecutive-quot-errors-quot-sorted-by/m-p/103981#M1476</link>
    <description>&lt;P&gt;I tried the non-realtime periodic search and I've yet find any results from it. I know there exists plenty of times where there's 3 CONFIDENCE=0 in a row. Not sure what else I can try.&lt;/P&gt;</description>
    <pubDate>Mon, 23 Jul 2012 00:12:27 GMT</pubDate>
    <dc:creator>Paxxxman</dc:creator>
    <dc:date>2012-07-23T00:12:27Z</dc:date>
    <item>
      <title>Setting an alert for consecutive "errors" sorted by another variable</title>
      <link>https://community.splunk.com/t5/Alerting/Setting-an-alert-for-consecutive-quot-errors-quot-sorted-by/m-p/103979#M1474</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I'm trying to set up an alert that checks for three '0' values in a row from the same "lane". If a non-zero value is found in between no alert is made. The transaction coming through from the logs looks like:&lt;/P&gt;

&lt;P&gt;NAME=2012_07_20_07_59_56_729_0_00004_00002.jpg,OCR=BJH27V,CONFIDENCE=563,STATE=NSW,LANE=4&lt;/P&gt;

&lt;P&gt;Basically, whenever there's three CONFIDENCE=0 in a row in the same LANE, I need an alert to be sent. I tried following some steps from another question posted here which used streamstats, but I'm not sure how to use it and also differentiate by lane.&lt;/P&gt;

&lt;P&gt;All help is appreciated! Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:07:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Setting-an-alert-for-consecutive-quot-errors-quot-sorted-by/m-p/103979#M1474</guid>
      <dc:creator>Paxxxman</dc:creator>
      <dc:date>2020-09-28T12:07:19Z</dc:date>
    </item>
    <item>
      <title>Re: Setting an alert for consecutive "errors" sorted by another variable</title>
      <link>https://community.splunk.com/t5/Alerting/Setting-an-alert-for-consecutive-quot-errors-quot-sorted-by/m-p/103980#M1475</link>
      <description>&lt;P&gt;With realtime search, you could use:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | dedup 3 LANE | stats count(CONFIDENCE==0) as count | where count==3
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;In a non-realtime periodic search, use:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | streamstats current=t window=3 global=f
        count(CONFIDENCE==0) as count
      by LANE
    | where count==3
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Then you can either just use a per-result alert for each LANE value (which you really should do for the realtime version), or get an alert whenever you get more than 0 results from this search. &lt;/P&gt;</description>
      <pubDate>Fri, 20 Jul 2012 00:10:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Setting-an-alert-for-consecutive-quot-errors-quot-sorted-by/m-p/103980#M1475</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2012-07-20T00:10:19Z</dc:date>
    </item>
    <item>
      <title>Re: Setting an alert for consecutive "errors" sorted by another variable</title>
      <link>https://community.splunk.com/t5/Alerting/Setting-an-alert-for-consecutive-quot-errors-quot-sorted-by/m-p/103981#M1476</link>
      <description>&lt;P&gt;I tried the non-realtime periodic search and I've yet find any results from it. I know there exists plenty of times where there's 3 CONFIDENCE=0 in a row. Not sure what else I can try.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jul 2012 00:12:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Setting-an-alert-for-consecutive-quot-errors-quot-sorted-by/m-p/103981#M1476</guid>
      <dc:creator>Paxxxman</dc:creator>
      <dc:date>2012-07-23T00:12:27Z</dc:date>
    </item>
  </channel>
</rss>

