All Apps and Add-ons

Trigger alert when over a proportion, but only include the select items on the attached CSV

MrMoody
Observer

I'm trying to create an alert that is triggered when event X is > 20% of a specific event type.

Once I have the trigger values, I want to include a CSV file that has the +20% transactions. So far I've been able to create the query to get the list for the CSV and a separate query that populates the necessary values for the alert condition, but I can't figure out how to attach a different CSV file to an alert, or to populate the alert with certain values while excluding others from the attachment that are necessary for the trigger condition.

Labels (2)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...