Alerting

How to create a custom alert when count of responseStatus>20?

vijaysubramania
Path Finder

My custom alert is triggering mails for zero events. Not sure why it's printing for 0 when responseStatus > 399

I have created the alert with condition responseStatus 499>20 ..Trigger an email. But it's printing zero record as well for every minute and triggering mail. Is it because of running the query in timechart instead of  using stats count or we should not create with stats count

(responseStatus>399)| dedup requestId | stats count by responseStatus

How to set custom alert for this? 

vijaysubramania_0-1596734296188.png

 

vijaysubramania_1-1596734317628.png

Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust
Please share your search.
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...