Alerting

Customer trigger for alerts

jephillips
Explorer

I'm looking for a way to setup a customer trigger for the below search. Basically I need the alert to go off if RespCode=60 is greater than 3%. When I try entering percentage as the Customer trigger Splunk says "In handler 'savedsearch': Cannot parse alert condition. Unknown search command 'percentage'." I uploaded a pic of the results if that helps.

index=main sourcetype=ivr host=apcv* card_validation response=* | stats count by RespCode | eventstats sum(count) as TotalofAllRespCodes | eval percentage=(count/TotalofAllRespCodes*100) | search RespCode=60

alt text

0 Karma
1 Solution

adayton20
Contributor

Based on the table you provided, you could add a |where percentage > 3 at the end of your search.

View solution in original post

adayton20
Contributor

Based on the table you provided, you could add a |where percentage > 3 at the end of your search.

jephillips
Explorer

Thanks. I do believe that will do it. I was over complicating things apparently.

0 Karma

burwell
SplunkTrust
SplunkTrust

What condition are you alerting on exactly? What is the alert criteria?

jephillips
Explorer

I want the alert to trigger if RespCode of 60 is greater than 3%.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...