Logic to find spike in metrics log

New Member
  • Hi All- Good Morning!

Need quick help to find spike of counter from last hour to current hour if it's 20X then it should trigger.

Using mstats and mcatalog.

Thanks in advance.


Currently i have pasted sample query to get the view over logging structure.

| Mcatalog values (stack) as stack values(node) as node values(db) as db values(inst) as inst where index= main and [| mstats avg(_value) as value where index=main and counter=Subject or( counter= wells) metric_name=metrices by inst counter span=10m

|Streamstats global=f window=2 range(value) as value by inst counter









Labels (1)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Data Preparation Made Easy: SPL2 for Edge Processor

By now, you may have heard the exciting news that Edge Processor, the easy-to-use Splunk data preparation tool ...

Introducing Edge Processor: Next Gen Data Transformation

We get it - not only can it take a lot of time, money and resources to get data into Splunk, but it also takes ...

Tips & Tricks When Using Ingest Actions

Tune in to learn about:Large scale architecture when using Ingest ActionsRegEx performance considerations ...