<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sending alert based on Threshold conditions in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Sending-alert-based-on-Threshold-conditions/m-p/384935#M6760</link>
    <description>&lt;P&gt;Oops I was not aware the editor does not support certain symbols. So here are the alerting conditions again&lt;/P&gt;

&lt;P&gt;xvalues&amp;lt;=100  no alerting&lt;BR /&gt;
xvalues&amp;gt;100 and &amp;lt;=200 warning&lt;BR /&gt;
xvalues&amp;gt;200 - Critical Alert&lt;/P&gt;</description>
    <pubDate>Thu, 11 Jul 2019 17:01:33 GMT</pubDate>
    <dc:creator>sajug</dc:creator>
    <dc:date>2019-07-11T17:01:33Z</dc:date>
    <item>
      <title>Sending alert based on Threshold conditions</title>
      <link>https://community.splunk.com/t5/Alerting/Sending-alert-based-on-Threshold-conditions/m-p/384934#M6759</link>
      <description>&lt;P&gt;Hello&lt;BR /&gt;
I have query that gets me x values every 5 minutes. Now what I am trying to achieve is, alert based on threshold conditions. For example&lt;/P&gt;

&lt;P&gt;index=xxx | timechart span=5m eval(round(avg(x),3)) as xvalues&lt;/P&gt;

&lt;P&gt;Condition for alerting below&lt;/P&gt;

&lt;P&gt;xvalues&amp;lt;100 no alert&lt;BR /&gt;
xvalues&amp;gt;100 and &amp;lt;200 - Warning alert&lt;BR /&gt;
xvalues&amp;gt;200 Critical&lt;/P&gt;

&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jul 2019 16:56:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Sending-alert-based-on-Threshold-conditions/m-p/384934#M6759</guid>
      <dc:creator>sajug</dc:creator>
      <dc:date>2019-07-11T16:56:27Z</dc:date>
    </item>
    <item>
      <title>Re: Sending alert based on Threshold conditions</title>
      <link>https://community.splunk.com/t5/Alerting/Sending-alert-based-on-Threshold-conditions/m-p/384935#M6760</link>
      <description>&lt;P&gt;Oops I was not aware the editor does not support certain symbols. So here are the alerting conditions again&lt;/P&gt;

&lt;P&gt;xvalues&amp;lt;=100  no alerting&lt;BR /&gt;
xvalues&amp;gt;100 and &amp;lt;=200 warning&lt;BR /&gt;
xvalues&amp;gt;200 - Critical Alert&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jul 2019 17:01:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Sending-alert-based-on-Threshold-conditions/m-p/384935#M6760</guid>
      <dc:creator>sajug</dc:creator>
      <dc:date>2019-07-11T17:01:33Z</dc:date>
    </item>
  </channel>
</rss>

