I want to generate an alert when my netflow count is something like 10% above the usual average count.
I got something like this but i don't know how to go further 😞
sourcetype="cisco:asa" earliest=-7d@d latest=@d | stats count by date_mday | eventstats avg(count)
can someone help me?
Give this a try (assuming you want to compare today's count with last 7 day's average count. If not adjust the relative_time value in eval period ).
sourcetype="cisco:asa" earliest=-7d@d latest=now | timechart span=1d count | eval period=if(_time>=relative_time(now(),"@d"),"today","last7days") | eval temp=1
| stats avg(count) as avgcount over temp by period | fields - temp
| where today>1.1*last7days
I get the error: Error in 'stats' command: The argument 'over' is invalid.