Splunk Enterprise

Bar Chart Alert

michaelsplunk1
Path Finder

Hi all!

I would like to set an alert on a bar chart. The bar chart shows the number of service desk tickets per each device.

How can I alert when one of these bars increases by five tickets within five minutes?

This is the query that produces the bar chart:

index=sample_index
| stats dc(ticket_number) by device_name 
| head 15

 

Thank you!

Labels (2)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Try something like this as the basis for your alert

index=sample_index
| bin _time span=1m
| stats dc(ticket_number) as tickets by _time device_name 
| streamstats time_window=5m earliest(tickets) as previous_tickets by device_name
| eval diff=tickets-previous_tickets
| where diff>4

This uses a rolling 5 minute window in case your increase happens across a 5 minute boundary 

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...

Auto-Injector for Everything Else: Making OpenTelemetry Truly Universal

You might have seen Splunk’s recent announcement about donating the OpenTelemetry Injector to the ...