Alerting

alert

vinod_52791
Engager

I want to send an alert when  response time > 10 sec is more than 2% of total transaction in an hour
could you please suggest proper query to achieve the above requirement.

Labels (1)
Tags (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| eval slow=if(response>10,1,0)
| bin _time span=1h
| stats count sum(slow) as slow by _time
| eval tooslow=100*slow/count
| where tooslow>2
0 Karma

vinod_52791
Engager

HI @ITWhisperer 

i want it as 10000 milliseconds
then how the query will be??

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Is your response field in milliseconds?

0 Karma

vinod_52791
Engager

hi @ITWhisperer 

 

Yes field in milliseconds

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| eval slow=if(response>10000,1,0)
| bin _time span=1h
| stats count sum(slow) as slow by _time
| eval tooslow=100*slow/count
| where tooslow>2
0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security: Your Command Center for PCI DSS Compliance

Every security professional knows the drill. The PCI DSS audit is approaching, and suddenly everyone's asking ...

Developer Spotlight with Guilhem Marchand

From Splunk Engineer to Founder: The Journey Behind TrackMe    After spending over 12 years working full time ...

Cisco Catalyst Center Meets Splunk ITSI: From 'Payments Are Down' to Root Cause in ...

The Problem: When Networks and Services Don't Talk Payment systems fail at a retail location. Customers are ...