<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to monitor deviation to log volume? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-monitor-deviation-to-log-volume/m-p/630355#M218993</link>
    <description>&lt;P&gt;What I am looking for might be something even simpler. If I can get the total log volume per day and set up a threshold for alerting that will work. I was thinking log volume for most indexes (log sources) do tend to drop on the weekends. Perhaps there is a threshold that can be set up based on the day of the week. Weekends vs week days. Any such way to accomplish this?&lt;/P&gt;</description>
    <pubDate>Thu, 09 Feb 2023 20:00:48 GMT</pubDate>
    <dc:creator>Splunk77</dc:creator>
    <dc:date>2023-02-09T20:00:48Z</dc:date>
    <item>
      <title>How to monitor deviation to log volume?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-monitor-deviation-to-log-volume/m-p/630314#M218978</link>
      <description>&lt;P&gt;I am trying to monitor drop in events per index. What is the best way to get a baseline and detect deviation to the volume? I am more interesting in drop in events and not increase.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Feb 2023 18:53:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-monitor-deviation-to-log-volume/m-p/630314#M218978</guid>
      <dc:creator>Splunk77</dc:creator>
      <dc:date>2023-02-09T18:53:17Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor deviation to log volume</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-monitor-deviation-to-log-volume/m-p/630325#M218982</link>
      <description>&lt;P&gt;Start with per_index_thruput in _internal.&amp;nbsp; It's just a sample and has natural ups and downs, but may give you something to work with.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal sourcetype=splunkd source=*metrics.log* group=per_index_thruput&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 09 Feb 2023 16:41:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-monitor-deviation-to-log-volume/m-p/630325#M218982</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-02-09T16:41:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to monitor deviation to log volume?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-monitor-deviation-to-log-volume/m-p/630355#M218993</link>
      <description>&lt;P&gt;What I am looking for might be something even simpler. If I can get the total log volume per day and set up a threshold for alerting that will work. I was thinking log volume for most indexes (log sources) do tend to drop on the weekends. Perhaps there is a threshold that can be set up based on the day of the week. Weekends vs week days. Any such way to accomplish this?&lt;/P&gt;</description>
      <pubDate>Thu, 09 Feb 2023 20:00:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-monitor-deviation-to-log-volume/m-p/630355#M218993</guid>
      <dc:creator>Splunk77</dc:creator>
      <dc:date>2023-02-09T20:00:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to monitor deviation to log volume?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-monitor-deviation-to-log-volume/m-p/630381#M219001</link>
      <description>&lt;P&gt;Check the Monitoring Console to see if it has a query that comes close to what you want.&lt;/P&gt;&lt;P&gt;As for accounting for weekends and holidays, you probably should look at the Machine Learning Toolkit (MLTK).&amp;nbsp; It has algorithms that can detect trends in your data and help find when the trends break.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2023 01:14:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-monitor-deviation-to-log-volume/m-p/630381#M219001</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-02-10T01:14:25Z</dc:date>
    </item>
  </channel>
</rss>

