Alerting

How to show 2 results within the same alert?

xvxt006
Contributor

Hi,

I have this search which gives me error % and good requests, etc. When I get this alert, I would also like to send an another table in the same alert results where I can show the top 5 URIs by the error status. Would it be possible?

 (status=200 OR status>399)  | eval requestType = if(status==200, "OK", "Error")  | chart count as requests  over host by requestType | rename "requests: OK" as OK ,"requests: Error" as Error   | eval TotalRequests= (OK+Error) | eval GoodRequestsPerc = round((OK/TotalRequests)*100,2) |   eval FailuresPerc = round((Error/TotalRequests)*100,2)  | table host, OK,Error,GoodRequestsPerc,  FailuresPerc | sort  -"FailuresPerc" | where FailuresPerc > 5
Tags (2)
0 Karma

otman01
Communicator

you can use this command :
| set union [ search 1] [ search 2]

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

🍂 Fall into November with a fresh lineup of Community Office Hours, Tech Talks, and Webinars we’ve ...

Transform your security operations with Splunk Enterprise Security

Hi Splunk Community, Splunk Platform has set a great foundation for your security operations. With the ...

Splunk Admins and App Developers | Earn a $35 gift card!

Splunk, in collaboration with ESG (Enterprise Strategy Group) by TechTarget, is excited to announce a ...