I would like to get alert if it exceeds threshold
eg:
Datafsused >=50
Log print:
Mar 26 16:12:05 127.0.0.1 fs_used_percentage_stats: Datafsused=43 Commitlogfsused=21 Backupfsused=81
Check if Datafsused field is extracted in the index. If yes, then you can directly filter events in your search like this:
index=<index_name> Datafsused >= 50
If not use rex command to extract Datafsused values and then use where command:
index=<index_name> | rex "Datafsused=(?<Datafsused>\d+)" | where Datafsused >= 50
Then save this as an alert and add alert action settings: Add to Triggered Alerts.
Thanks for your quick help!
Check if Datafsused field is extracted in the index. If yes, then you can directly filter events in your search like this:
index=<index_name> Datafsused >= 50
If not use rex command to extract Datafsused values and then use where command:
index=<index_name> | rex "Datafsused=(?<Datafsused>\d+)" | where Datafsused >= 50
Then save this as an alert and add alert action settings: Add to Triggered Alerts.