Hi all!
I would like to set an alert on a bar chart. The bar chart shows the number of service desk tickets per each device.
How can I alert when one of these bars increases by five tickets within five minutes?
This is the query that produces the bar chart:
index=sample_index
| stats dc(ticket_number) by device_name
| head 15
Thank you!
Try something like this as the basis for your alert
index=sample_index
| bin _time span=1m
| stats dc(ticket_number) as tickets by _time device_name
| streamstats time_window=5m earliest(tickets) as previous_tickets by device_name
| eval diff=tickets-previous_tickets
| where diff>4
This uses a rolling 5 minute window in case your increase happens across a 5 minute boundary