Alerting

Generalize alerts for detecting performance metric regressions for all type of machines into one

phoenix_ivy
Observer

Hi Team, I want to consult with you about the following situation:

I setup an email alert for detecting a specific performance metric of one type of machine (config=A). The alert will raise when it detect the latest run value is regressed >5% than the last run value of the same type of machine (config=A).

However, this alert can only detect this for one machine (config=A). If we need to track many other machines (config=A, B, C, D), each one need an alert setup like this since each type of machine's value can only be compared with itself, which is very cumbersome considering we also need to monitor other performance metrics for all machines. 

Do we have a better way to create generalized these alerts into one for this case? Say an alert can loop all type of machines, fetch and compare a specific performance metrics and raise alert accordingly?

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Gather all your stats in one search and get the previous values by config (and metric type?), then do the comparisons. Generate alerts for each result which matches your criteria

0 Karma

phoenix_ivy
Observer

Thanks! However, gather all stats in one search would merge all configs data. If I compare the last two runs data that came from two different configs, the regression result would be invalid.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Yes, I said "Gather all your stats in one search and get the previous values by config ..." - this means, use the by clause.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...