Alerting

How to create a custom alert when count of responseStatus>20?

vijaysubramania
Path Finder

My custom alert is triggering mails for zero events. Not sure why it's printing for 0 when responseStatus > 399

I have created the alert with condition responseStatus 499>20 ..Trigger an email. But it's printing zero record as well for every minute and triggering mail. Is it because of running the query in timechart instead of  using stats count or we should not create with stats count

(responseStatus>399)| dedup requestId | stats count by responseStatus

How to set custom alert for this? 

vijaysubramania_0-1596734296188.png

 

vijaysubramania_1-1596734317628.png

Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust
Please share your search.
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

🍂 Fall into November with a fresh lineup of Community Office Hours, Tech Talks, and Webinars we’ve ...

Transform your security operations with Splunk Enterprise Security

Hi Splunk Community, Splunk Platform has set a great foundation for your security operations. With the ...

Splunk Admins and App Developers | Earn a $35 gift card!

Splunk, in collaboration with ESG (Enterprise Strategy Group) by TechTarget, is excited to announce a ...