Alerting

How to set up an alert based on a threshold which is dynamically updated based on the previous day's maximum value? Thanks!!

bhavik175
New Member

I am trying to create an alert to monitor counts on a per hour basis. I would like to set up a dynamic threshold based on the previous day's maximum value + 20% of the max value. Is there a way we can do this in splunk?

0 Karma

woodcock
Esteemed Legend

Try this:

MySearchStr earliest=-1d@d latest=0d@d | stats max(MyField) AS yesterdayMax | map search="MySearchStr | where MyField>$yesterdayMax$"

0 Karma

HattrickNZ
Motivator

If i run this will I get a value fof zero or 1 in the visualisation tab?
Is $yesterdayMax$ a variable from the 1st part of the search?

I tried to runt it a couple of times, different ways and I was getting no results found

0 Karma

somesoni2
Revered Legend

You want to check the count every hour and compare the count for current hour with 1.2 times max count per hour from yesterday?

0 Karma
Get Updates on the Splunk Community!

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...