Alerting

Unbalanced Load Alert

alamo1212
New Member

I want to be alerted when the motor load on a machine is more than 10 higher or lower than the other motor load (they should usually be balanced and share the load evenly. Unbalanced load could lead to a failure).

Would I essentially need to build two alerts for this? One for alerting when Z is 10 higher than Y, and another for when Z motor is 10 lower than Y? Or can it be done in one?

If ZLoad > (YLoad +10) when [tag]=STOPPED

0 Karma

somesoni2
Revered Legend

You can do both in One. Something like this:

your current search fetching zLoad and YLoad
| eval diff=zLoad-YLoad , eval type=if(diff>0,"Higher","Lower")
| where abs(diff)>=10
0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...