Alerting

Customer trigger for alerts

jephillips
Explorer

I'm looking for a way to setup a customer trigger for the below search. Basically I need the alert to go off if RespCode=60 is greater than 3%. When I try entering percentage as the Customer trigger Splunk says "In handler 'savedsearch': Cannot parse alert condition. Unknown search command 'percentage'." I uploaded a pic of the results if that helps.

index=main sourcetype=ivr host=apcv* card_validation response=* | stats count by RespCode | eventstats sum(count) as TotalofAllRespCodes | eval percentage=(count/TotalofAllRespCodes*100) | search RespCode=60

alt text

0 Karma
1 Solution

adayton20
Contributor

Based on the table you provided, you could add a |where percentage > 3 at the end of your search.

View solution in original post

adayton20
Contributor

Based on the table you provided, you could add a |where percentage > 3 at the end of your search.

jephillips
Explorer

Thanks. I do believe that will do it. I was over complicating things apparently.

0 Karma

burwell
SplunkTrust
SplunkTrust

What condition are you alerting on exactly? What is the alert criteria?

jephillips
Explorer

I want the alert to trigger if RespCode of 60 is greater than 3%.

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...