Knowledge Management

Using Summary Index for deviation

kunadkat
Explorer

How can I accomplish the following:
- Count average number of apache access_common entries span=15m and put it in the summary index(I have to run this everyday)
- Compare realtime data average with 2 weeks ago's summary index data and generate alert if realtime average is 20 percent more summary index data from 14 days ago.

Thanks,

Tags (1)
0 Karma

richcollier
Path Finder
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...