Alerting

How to show 2 results within the same alert?

xvxt006
Contributor

Hi,

I have this search which gives me error % and good requests, etc. When I get this alert, I would also like to send an another table in the same alert results where I can show the top 5 URIs by the error status. Would it be possible?

 (status=200 OR status>399)  | eval requestType = if(status==200, "OK", "Error")  | chart count as requests  over host by requestType | rename "requests: OK" as OK ,"requests: Error" as Error   | eval TotalRequests= (OK+Error) | eval GoodRequestsPerc = round((OK/TotalRequests)*100,2) |   eval FailuresPerc = round((Error/TotalRequests)*100,2)  | table host, OK,Error,GoodRequestsPerc,  FailuresPerc | sort  -"FailuresPerc" | where FailuresPerc > 5
Tags (2)
0 Karma

otman01
Communicator

you can use this command :
| set union [ search 1] [ search 2]

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...