Alerting

How to use the value of a column as a trigger an alert

trunghung
Path Finder

I currently have a table with 3 columns that was created from a few column append search queries.
count count count
Error | day1 | day2 | day3 | % betwen 1 & 2 | % between 1 & 3
Err A | 2 | 4 | 2 | 100% | 0%
Err B | 4 | 5 | 6 | 25% | 50%
Err C |blank | 5 | 6 | infinite % | infinite%

I would like to have an alert that that it would alert me if the increase between days is over 50% on any of the row. Is it possible to do something like that? thank you very much.

Tags (1)
0 Karma

somesoni2
Revered Legend

Assuming your field names are exactly as they appear in your question above, try this search as the alert search and set "number of events greater than 0" as alert condition

your current search giving above output with fields Error, day1, day2, day3, "% betwen 1 & 2", "% between 1 & 3" 
| where '% between 1 & 3'>50 OR '% between 1 & 2' >50

If you only have fields Error, day1, day2, day3, they try something like this

your current search giving above output with fields Error, day1, day2, day3 | where (day1/day2)>0.5 OR (day1/day3)>0.5
0 Karma
Get Updates on the Splunk Community!

Optimize Cloud Monitoring

  TECH TALKS Optimize Cloud Monitoring Tuesday, August 13, 2024  |  11:00AM–12:00PM PST   Register to ...

What's New in Splunk Cloud Platform 9.2.2403?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2403! Analysts can ...

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...