Alerting

Logic to find spike in metrics log

KS37
New Member
  • Hi All- Good Morning!

Need quick help to find spike of counter from last hour to current hour if it's 20X then it should trigger.

Using mstats and mcatalog.

Thanks in advance.

 

Currently i have pasted sample query to get the view over logging structure.

| Mcatalog values (stack) as stack values(node) as node values(db) as db values(inst) as inst where index= main and [| mstats avg(_value) as value where index=main and counter=Subject or( counter= wells) metric_name=metrices by inst counter span=10m

|Streamstats global=f window=2 range(value) as value by inst counter

 

 

 

 

 

 

 

 

Labels (1)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...