Alerting

alert

vinod_52791
Engager

HI 

i am getting below response from my Splunk query, please refer below screenshot

vinod_52791_0-1637575852875.png

If you see the above screenshot you can see the result is 92.20%,my requirement is i need to send an alert when ever the percentage is below98.00%

so could you please suggest proper query in order to trigger an alert when ever the result from query is below 98.00% in a time frame of 1 hour

Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Remove the "%" from successrate.  Add | where successrate < 98 to the end of the query.  If necessary, you can use an eval after that to put the "%" back.  Configure the alert to trigger if there are more than zero results returned by the query.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...