Alerting

Customer trigger for alerts

jephillips
Explorer

I'm looking for a way to setup a customer trigger for the below search. Basically I need the alert to go off if RespCode=60 is greater than 3%. When I try entering percentage as the Customer trigger Splunk says "In handler 'savedsearch': Cannot parse alert condition. Unknown search command 'percentage'." I uploaded a pic of the results if that helps.

index=main sourcetype=ivr host=apcv* card_validation response=* | stats count by RespCode | eventstats sum(count) as TotalofAllRespCodes | eval percentage=(count/TotalofAllRespCodes*100) | search RespCode=60

alt text

0 Karma
1 Solution

adayton20
Contributor

Based on the table you provided, you could add a |where percentage > 3 at the end of your search.

View solution in original post

adayton20
Contributor

Based on the table you provided, you could add a |where percentage > 3 at the end of your search.

jephillips
Explorer

Thanks. I do believe that will do it. I was over complicating things apparently.

0 Karma

burwell
SplunkTrust
SplunkTrust

What condition are you alerting on exactly? What is the alert criteria?

jephillips
Explorer

I want the alert to trigger if RespCode of 60 is greater than 3%.

0 Karma
Get Updates on the Splunk Community!

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...

Brains, Bytes, and Boston: Learn from the Best at .conf25

When you think of Boston, you might picture colonial charm, world-class universities, or even the crack of a ...