Monitoring Splunk

Monitoring 15% drop in logins with delta

hornettj
New Member

Hi bit of background, I am trying to monitor a 15% drop in logins using the delta command at the moment over Last 15mins

I am using the below search as my test:
index=*_XXXX_app AND (/security/session) | eval call=case(uri like "/security/session%","Login") | timechart count span=5m | delta count as difference | eval percdif=round(abs(difference/count)*100,0)

My Final Search which I will use to create an alert is:
index=*_XXXX_app AND (/security/session) | eval call=case(uri like "/security/session%","Login") | timechart count span=5m | delta count as difference | eval percdif=round(abs(difference/count)*100,0) | where percdif>=15 AND difference<0 | eval mesg="Suspected Service Impact 15 Percent drop in Traffic" | table _time mesg

The problem I have is it keeps triggering against the last minute

example if I run it I get

_time count difference percdif
2016-02-14 08:45:00 258

2016-02-14 08:50:00 377 119 32
2016-02-14 08:55:00 358 -19 5
2016-02-14 09:00:00 15 -343 2287

It does not like the first and last minute of data, do I need to find away to get it to ignore the last minute?

Tags (1)
0 Karma

renjith_nair
Legend

Try the option partial=false in timechart to exclude the partial buckets(beginning and end)

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma

hornettj
New Member

Unfortunately that still did not work

I think I found a work around by using a relative searc
Relative:
Earliest = 12min “Beginning of minute”
Latest = “Beginning of current minute”

So far its behaving

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...