<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to trigger this type of a alert? in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/How-to-trigger-this-type-of-a-alert/m-p/398542#M7014</link>
    <description>&lt;P&gt;Mayur - I don't think you understood my question. I have to trigger an alert &lt;STRONG&gt;iff&lt;/STRONG&gt; the response time is greater than 10 sec even after 30 mins, &lt;STRONG&gt;i.e. for first 30 mins, no alert. 30 mins 1 sec(if still the response time is &amp;gt;10s), the alert has to be triggered.&lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 15 May 2018 10:21:49 GMT</pubDate>
    <dc:creator>tchintam</dc:creator>
    <dc:date>2018-05-15T10:21:49Z</dc:date>
    <item>
      <title>How to trigger this type of a alert?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-trigger-this-type-of-a-alert/m-p/398538#M7010</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have these events from where I calculate response time for the particular ping. The events are generated randomly and not at any particular time. So, I want to create an alert in such a way that if the response time is greater than 10 sec for more than 30 mins, it should trigger an alert. How do I go about it?&lt;/P&gt;</description>
      <pubDate>Tue, 15 May 2018 09:02:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-trigger-this-type-of-a-alert/m-p/398538#M7010</guid>
      <dc:creator>tchintam</dc:creator>
      <dc:date>2018-05-15T09:02:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to trigger this type of a alert?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-trigger-this-type-of-a-alert/m-p/398539#M7011</link>
      <description>&lt;P&gt;can you provide the search to calculate response time?&lt;BR /&gt;
you can use &lt;CODE&gt;timechart&lt;/CODE&gt; command to segregate the response time.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;base search with response time and time&amp;gt;| timechart span=30m sum(response_time) as response_time | where response_time&amp;gt;10
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Assuming that response time is in seconds already otherwise you would need to convert to seconds intially.&lt;/P&gt;

&lt;P&gt;Let me know if this helps!&lt;/P&gt;</description>
      <pubDate>Tue, 15 May 2018 09:54:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-trigger-this-type-of-a-alert/m-p/398539#M7011</guid>
      <dc:creator>mayurr98</dc:creator>
      <dc:date>2018-05-15T09:54:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to trigger this type of a alert?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-trigger-this-type-of-a-alert/m-p/398540#M7012</link>
      <description>&lt;P&gt;The response time is already in seconds. Could you please explain the timechart span=30m that you used?&lt;/P&gt;</description>
      <pubDate>Tue, 15 May 2018 10:03:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-trigger-this-type-of-a-alert/m-p/398540#M7012</guid>
      <dc:creator>tchintam</dc:creator>
      <dc:date>2018-05-15T10:03:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to trigger this type of a alert?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-trigger-this-type-of-a-alert/m-p/398541#M7013</link>
      <description>&lt;P&gt;I think this doc would explain it better:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/7.1.0/SearchReference/Timechart"&gt;http://docs.splunk.com/Documentation/Splunk/7.1.0/SearchReference/Timechart&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;timechart will make a bin of span of 30 minutes and in that 30 minutes, it will check for the response time greater than 10 specified in the where clause.&lt;/P&gt;</description>
      <pubDate>Tue, 15 May 2018 10:09:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-trigger-this-type-of-a-alert/m-p/398541#M7013</guid>
      <dc:creator>mayurr98</dc:creator>
      <dc:date>2018-05-15T10:09:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to trigger this type of a alert?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-trigger-this-type-of-a-alert/m-p/398542#M7014</link>
      <description>&lt;P&gt;Mayur - I don't think you understood my question. I have to trigger an alert &lt;STRONG&gt;iff&lt;/STRONG&gt; the response time is greater than 10 sec even after 30 mins, &lt;STRONG&gt;i.e. for first 30 mins, no alert. 30 mins 1 sec(if still the response time is &amp;gt;10s), the alert has to be triggered.&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 May 2018 10:21:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-trigger-this-type-of-a-alert/m-p/398542#M7014</guid>
      <dc:creator>tchintam</dc:creator>
      <dc:date>2018-05-15T10:21:49Z</dc:date>
    </item>
  </channel>
</rss>

