Alerting

Custom alert condition

ranjani
New Member

I want to compare the results from latest 4 hrs today with the results from the same time yesterday and want to set an alert if today's result drops by 20 percent.

My search string is:

index="abcd" earliest=-28h latest=-24h | stats count as prevday |
append [ search index="abcd" earliest=-4h latest=now | stats count as currday] | eval diff = (abs(prevday - currday)/prevday)*100

Using this search string I could store the results in respective variables prevday and currday.. But I could not successfully set an alert by mentioning the custom condition diff > 20. Where am I doing a mistake? What do I need to specify in alert condition so that I will get an alert if diff > 20 ?

Tags (1)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

By using append you're getting two rows in your result, while eval will operate on each row individually. Put this before your eval:

... | stats first(prevday) as prevday first(currday) as currday | ...

That will collapse the two rows into one, letting eval see both columns properly.

View solution in original post

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

By using append you're getting two rows in your result, while eval will operate on each row individually. Put this before your eval:

... | stats first(prevday) as prevday first(currday) as currday | ...

That will collapse the two rows into one, letting eval see both columns properly.

0 Karma

ranjani
New Member

Oh cool. This really worked for me. Appreciate your help 🙂

0 Karma
Get Updates on the Splunk Community!

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...