Alerting

Add Alert for Dashboard Panel

tkwaller
Builder

Hello

I'm trying to add an alert to a dashboard panel: here is the base search:
index=name app_name=API brokerId=* operation=purchase earliest=-4h | xmlkv | timechart span=10min count by transactionType | eval NRTPCT=(NonRealTime/(RealTime+NonRealTime))*100 | eval RTPCT=(RealTime/(RealTime+NonRealTime))*100

What I would like to alert on is when the NRTPCT goes over 2%

I haven't figured out the conditional search for the alert to use.

Can anyone help?

Tags (1)
0 Karma
1 Solution

tkwaller
Builder

Nevermind, changed the base search, added a new field for eval and used that field to determine the conditional search for the alert.

View solution in original post

0 Karma

tkwaller
Builder

Nevermind, changed the base search, added a new field for eval and used that field to determine the conditional search for the alert.

0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...