Knowledge Management

Using Summary Index for deviation

kunadkat
Explorer

How can I accomplish the following:
- Count average number of apache access_common entries span=15m and put it in the summary index(I have to run this everyday)
- Compare realtime data average with 2 weeks ago's summary index data and generate alert if realtime average is 20 percent more summary index data from 14 days ago.

Thanks,

Tags (1)
0 Karma

richcollier
Path Finder
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...