Alerting

Need help on Alert Custom Trigger for a returned Search Percentage

mninansplunk
Path Finder

Hello,

I have the following Search that returns a percent_difference value.

sourcetype="orderdetail-prod"|stats count(PriceModelLevel) AS total, count(eval(PriceModelLevel="DEFAULT_SITEONE_LIST")) AS Default_Siteone_List|eval percent_difference=((Default_Siteone_List/total)*100) | table percent_difference

 

However, I can't figure out how to trigger an alert if the percentage_difference is >=20.  I tried:

search percentage_difference >=20

Does this seem correct?  If so, perhaps another setting in the Alert config is mucking it up as it never is triggered.

Thanks for any help you can give.

 

 

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

I find I get better results by doing all the filtering in my query and having the alert trigger if the number of results is not zero.

sourcetype="orderdetail-prod"
| stats count(PriceModelLevel) AS total, count(eval(PriceModelLevel="DEFAULT_SITEONE_LIST")) AS Default_Siteone_List
| eval percent_difference=((Default_Siteone_List/total)*100) 
| where percent_difference >= 20
---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

I find I get better results by doing all the filtering in my query and having the alert trigger if the number of results is not zero.

sourcetype="orderdetail-prod"
| stats count(PriceModelLevel) AS total, count(eval(PriceModelLevel="DEFAULT_SITEONE_LIST")) AS Default_Siteone_List
| eval percent_difference=((Default_Siteone_List/total)*100) 
| where percent_difference >= 20
---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...