Alerting

Splunk Dashboard and Alert for traffic distribution comparsion

asplunk789
Loves-to-Learn Everything

Want to create a Splunk alert for Servers traffic distribution. I have 100's of different type servers in each data center (like app servers, db servers etc.). I can create a dashboard and splunk alert for specific set of servers.

But here I want to create this dashboard and splunk alert on basis of datacenter.

So how I can create this type of requirement ? 

Per host wise, below query I written for reference, But data center wise all hosts can i put it in one query and write ? 

index=* | where host like "ANCLOPR%" | bin span=5m _time | stats count BY _time host | eventstats sum(count) as total by _time | eval percent = count / total*100 | chart values(percent) by _time host usenull=f useother=f limit=100

 

 

 

Labels (1)
0 Karma

asplunk789
Loves-to-Learn Everything

Traffic distribution should be equally distributed for each server and if any difference, we can trigger an alert for specific servers not in equal distribution.

0 Karma
Get Updates on the Splunk Community!

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...

Observability protocols to know about

Observability protocols define the specifications or formats for collecting, encoding, transporting, and ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...