Alerting

Splunk Dashboard and Alert for traffic distribution comparsion

asplunk789
Loves-to-Learn Everything

Want to create a Splunk alert for Servers traffic distribution. I have 100's of different type servers in each data center (like app servers, db servers etc.). I can create a dashboard and splunk alert for specific set of servers.

But here I want to create this dashboard and splunk alert on basis of datacenter.

So how I can create this type of requirement ? 

Per host wise, below query I written for reference, But data center wise all hosts can i put it in one query and write ? 

index=* | where host like "ANCLOPR%" | bin span=5m _time | stats count BY _time host | eventstats sum(count) as total by _time | eval percent = count / total*100 | chart values(percent) by _time host usenull=f useother=f limit=100

 

 

 

Labels (1)
0 Karma

asplunk789
Loves-to-Learn Everything

Traffic distribution should be equally distributed for each server and if any difference, we can trigger an alert for specific servers not in equal distribution.

0 Karma
Get Updates on the Splunk Community!

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...