Hi,
I would like to monitor one value of each event. When it keeps increasing after 5 events, an alarm should be triggert. I uase autoregress to generate the difference between the current event and previous event (see below). But how can I monitor that the difference keeps being positive after five events? Thank you very much!
| autoregress C_avg as C_avg_prev
| eval C_detal=C_avg-C_avg_prev
Try like this
| makeresults | eval C_avg="12 14 15 4 20 22 24 28 34 45 8 90" | makemv C_avg | mvexpand C_avg | table C_avg | rename comment as "Above generates sample data. replace it with your search"
| autoregress C_avg as C_avg_prev
| eval C_detla=C_avg-C_avg_prev
| eval C_trend=if(C_avg>C_avg_prev,1,0)
| streamstats sum(C_trend) as sum_C_trend window=5
| where sum_C_trend=5