Alerting

Need help on Alert Custom Trigger for a returned Search Percentage

mninansplunk
Path Finder

Hello,

I have the following Search that returns a percent_difference value.

sourcetype="orderdetail-prod"|stats count(PriceModelLevel) AS total, count(eval(PriceModelLevel="DEFAULT_SITEONE_LIST")) AS Default_Siteone_List|eval percent_difference=((Default_Siteone_List/total)*100) | table percent_difference

 

However, I can't figure out how to trigger an alert if the percentage_difference is >=20.  I tried:

search percentage_difference >=20

Does this seem correct?  If so, perhaps another setting in the Alert config is mucking it up as it never is triggered.

Thanks for any help you can give.

 

 

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

I find I get better results by doing all the filtering in my query and having the alert trigger if the number of results is not zero.

sourcetype="orderdetail-prod"
| stats count(PriceModelLevel) AS total, count(eval(PriceModelLevel="DEFAULT_SITEONE_LIST")) AS Default_Siteone_List
| eval percent_difference=((Default_Siteone_List/total)*100) 
| where percent_difference >= 20
---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

I find I get better results by doing all the filtering in my query and having the alert trigger if the number of results is not zero.

sourcetype="orderdetail-prod"
| stats count(PriceModelLevel) AS total, count(eval(PriceModelLevel="DEFAULT_SITEONE_LIST")) AS Default_Siteone_List
| eval percent_difference=((Default_Siteone_List/total)*100) 
| where percent_difference >= 20
---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...