Alerting

Trigger alert on a calculated value

wlbaird
Engager

My search ends with:

...

| stats count(Request) as RequestCnt,  count(FailedRequest) FailedRequestCnt

| eval FaildRequestPercentage =  RequestCnt / FailedRequestCnt * 100

How would I specify a trigger for FaildRequestPercentage  > 10?

How would I include: RequestCnt, FailedRequestCnt , and FaildRequestPercentage values in my alert message?

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Have the alert trigger when the number of results is not zero and let the query determine when the alert triggers.

...
| stats count(Request) as RequestCnt,  count(FailedRequest) FailedRequestCnt
| eval FaildRequestPercentage =  RequestCnt / RequestCnt * 100
| where FaildRequestPercentage > 10
| table RequestCnt RequestCnt FaildRequestPercentage 
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...