Hello
I would like to trigger an alert if value "pending" is above a value ( > 500) for a period of time (> 5 min).
If during those 5 minutes, the value go under 500 I don't want the alert to be triggered.
Here is the alert if above 500
index=my_index sourcetype=source:type "request(s) still pending"
| rex field=_raw "(?ms)^(?:[^ \\n]* ){7}(?P<pending>\\d+)" | where pending > 500
How can I add the alert only if value is above 500 for more than 5minutes?
hi @jbrolland ,
You can schedule the alert every five minutes and in the search query check if the minimum pending value is greater than 500 in the last five minutes. If yes, then raise an alert.
index=my_index sourcetype=source:type "request(s) still pending"
| rex field=_raw "(?ms)^(?:[^ \\n]* ){7}(?P<pending>\\d+)"
| stats min(pending) as min_pending_value
| where min_pending_value > 500
If this reply helps you, an upvote/like would be appreciated.
hi @jbrolland ,
You can schedule the alert every five minutes and in the search query check if the minimum pending value is greater than 500 in the last five minutes. If yes, then raise an alert.
index=my_index sourcetype=source:type "request(s) still pending"
| rex field=_raw "(?ms)^(?:[^ \\n]* ){7}(?P<pending>\\d+)"
| stats min(pending) as min_pending_value
| where min_pending_value > 500
If this reply helps you, an upvote/like would be appreciated.
Very smart, thanks!