All Apps and Add-ons

Splunk Alert - Threshold Breach Sustained For 30 MInutes

victorcorrea
Path Finder

Hi all,

I need to create an alert that will be triggered when a latency threshold is breached for sustained 30 minutes.

I am doing my research on how to incorporate streamstats into my query, and so far I have come up with this:

 

 

index="x" source="y" EndtoEnd
| rex (?<e2e_p>\d+)ms \\Extracts the numerical value from the e2e_p field.
| where isnotnull(e2e_p)
| streamstats avg(e2e_p) window=1800 current=t time_window=30m as avg_e2e_p
| where avg_e2e_p > 500

 

 

The condition doesn't happen often, but I'll work with the team that supports the app to simulate the condition once the query is finalized.

I have never used streamstats before, but that's what has come up in my search for a means to incoporate a sliding window into a SPL query.

Thank you in advance for taking the time to help with this.

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...