Alerting

How to edit my search for an alert to be triggered if a host's CPU load percentage exceeds 60%?

xuanyun
Path Finder

We use the following search to obtain information on Percent_CPU_Load.

index=os sourcetype=cpu | multikv fields pctIdle | eval Percent_CPU_Load = 100 - pctIdle | timechart avg(Percent_CPU_Load) by host

The search results show the Percent_CPU_Load of all the hosts.

I want an alert to be triggered when Percent_CPU_Load if any one of the hosts exceeds 60%.
How do I set the alert to meet the conditions above?

Tags (4)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

Try this search:

index=os sourcetype=cpu | multikv fields pctIdle | eval Percent_CPU_Load = 100 - pctIdle | stats avg(Percent_CPU_Load) as avg_cpu by host | where avg_cpu > 60

Set the alert to trigger when there is more than zero results.

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

Try this search:

index=os sourcetype=cpu | multikv fields pctIdle | eval Percent_CPU_Load = 100 - pctIdle | stats avg(Percent_CPU_Load) as avg_cpu by host | where avg_cpu > 60

Set the alert to trigger when there is more than zero results.

xuanyun
Path Finder

Thank you very much!
That's very kind of you!

Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...