Hello,
I have the following Search that returns a percent_difference value.
sourcetype="orderdetail-prod"|stats count(PriceModelLevel) AS total, count(eval(PriceModelLevel="DEFAULT_SITEONE_LIST")) AS Default_Siteone_List|eval percent_difference=((Default_Siteone_List/total)*100) | table percent_difference
However, I can't figure out how to trigger an alert if the percentage_difference is >=20. I tried:
search percentage_difference >=20
Does this seem correct? If so, perhaps another setting in the Alert config is mucking it up as it never is triggered.
Thanks for any help you can give.
I find I get better results by doing all the filtering in my query and having the alert trigger if the number of results is not zero.
sourcetype="orderdetail-prod"
| stats count(PriceModelLevel) AS total, count(eval(PriceModelLevel="DEFAULT_SITEONE_LIST")) AS Default_Siteone_List
| eval percent_difference=((Default_Siteone_List/total)*100)
| where percent_difference >= 20
I find I get better results by doing all the filtering in my query and having the alert trigger if the number of results is not zero.
sourcetype="orderdetail-prod"
| stats count(PriceModelLevel) AS total, count(eval(PriceModelLevel="DEFAULT_SITEONE_LIST")) AS Default_Siteone_List
| eval percent_difference=((Default_Siteone_List/total)*100)
| where percent_difference >= 20