AppD Archive

Testing baseline value in health rule.

CommunityUser
Splunk Employee
Splunk Employee

How do I set a health rule against the baseline value? E.g. If the baseline value is 100 and the actual value is 50% lower I want an alert. However, if the baseline is 3 and the actual is 1 I don’t want an alert. I only want an alert if the baseline value is greater than 20.

CommunityUser
Splunk Employee
Splunk Employee

With the more recent versions is it now possible to check baseline value in a health alert?

Arun_Dasetty
Super Champion

Hi Shaun,

 As of now we do not see an option as such to validate current metric data with particular baseline value, we currently have options only to compare current metric data > particular static value and we see options for to compare against baselines interms of multiple deviations and and baseline % which you are aware of , we request you to best utilize the current available settings and we see baseline is some thing calculated over past data and comparing against particular value may not better appraoch as the baseline varies as per new load in future, please correct me if i am wrong .

image.png

image.png

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...