I want to send an alert when response time > 10 sec is more than 2% of total transaction in an hour
could you please suggest proper query to achieve the above requirement.
| eval slow=if(response>10,1,0)
| bin _time span=1h
| stats count sum(slow) as slow by _time
| eval tooslow=100*slow/count
| where tooslow>2
HI @ITWhisperer
i want it as 10000 milliseconds
then how the query will be??
Is your response field in milliseconds?
| eval slow=if(response>10000,1,0)
| bin _time span=1h
| stats count sum(slow) as slow by _time
| eval tooslow=100*slow/count
| where tooslow>2