Alerting

Create search for alert on multiple values

srs20
New Member

I have time series data and am trying to search and create alerts.Sample data below

Id,timestamp,value
1,06/19/2019 10:00:00,6.2
2,06/19/2019 10:00:00,5.3
1,06/19/2019 10:05:00,6.1
2,06/19/2019 10:05:00,6.1
2,06/19/2019 10:10:00,6.6
1,06/19/2019 10:10:00,5.7

Alert when multiple id values exceed a threshold in a given time span.So,in the example above my search should generate an alert when Id's 1 and 2 both exceed a value of 5 in the last 10 minutes but not otherwise. How would I do this in SPL .Thanks for your help.

Tags (2)
0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...