AppD Archive

How to monitor low frequency calls

CommunityUser
Splunk Employee
Splunk Employee

Does anyone have any advice on if it is possible to monitor low frequecy calls so that false alerts aren't sent.

i.e. we only have ~1call min, but would expect 30-50 calls in one hour, to get a statistically meaningfull result would mean that you would need to sum up mayber 30 minutes of activity to see an effective drop of in the signal\rate to send an alert, I think to solve this we would really need the resolution to be at the hour level and not the minute.

Any suggestions?

Thanks

Graham

0 Karma

CommunityUser
Splunk Employee
Splunk Employee

Hi Graham,

If I understand it correctly, you want to configure HealthRule based on the number of minutes/hour of data. If my understanding is correct, you have a configuration setting for it which can be done from controller UI Console screen. Please see attached screen for reference. 

Let me know if my understanding is incorrect. 

Thanks,

Vishnu

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...