Alerting

How to enable an anomaly detection whenever there is a change in value of a field?

simon21
Path Finder

I have a field called capacity. I want to enable anomaly detection whenever there is a change in value of capacity (increments or decrements). So, if capacity value for a source "A" is "10" at 7th dec 14:40pm, and at 7th Dec 15:15pm, the capacity of source "A" is "12", then i want to be notified via an alert. Please help. Thanks!

0 Karma

sundareshr
Legend

I believe what you need is anomalousvalue. Try this, set your alert to trigger if count>0

base search | anomalousvalue capacity action=filter
0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...