Alerting

Need help on Alert Custom Trigger for a returned Search Percentage

mninansplunk
Path Finder

Hello,

I have the following Search that returns a percent_difference value.

sourcetype="orderdetail-prod"|stats count(PriceModelLevel) AS total, count(eval(PriceModelLevel="DEFAULT_SITEONE_LIST")) AS Default_Siteone_List|eval percent_difference=((Default_Siteone_List/total)*100) | table percent_difference

 

However, I can't figure out how to trigger an alert if the percentage_difference is >=20.  I tried:

search percentage_difference >=20

Does this seem correct?  If so, perhaps another setting in the Alert config is mucking it up as it never is triggered.

Thanks for any help you can give.

 

 

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

I find I get better results by doing all the filtering in my query and having the alert trigger if the number of results is not zero.

sourcetype="orderdetail-prod"
| stats count(PriceModelLevel) AS total, count(eval(PriceModelLevel="DEFAULT_SITEONE_LIST")) AS Default_Siteone_List
| eval percent_difference=((Default_Siteone_List/total)*100) 
| where percent_difference >= 20
---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

I find I get better results by doing all the filtering in my query and having the alert trigger if the number of results is not zero.

sourcetype="orderdetail-prod"
| stats count(PriceModelLevel) AS total, count(eval(PriceModelLevel="DEFAULT_SITEONE_LIST")) AS Default_Siteone_List
| eval percent_difference=((Default_Siteone_List/total)*100) 
| where percent_difference >= 20
---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...