Splunk IT Service Intelligence

Why am I intermittently getting fake alerts in bulk when I have made the base search and set the alerting on behalf of that?


I have made the base search and set alerting on behalf of that but i am intermittently getting fake alerts in bulk

this is the base search

index=vmware* (sourcetype=vmware:perf:cpu OR sourcetype=vmware:perf:mem) source=*virtual* |stats avg(p_average_cpu_usage_percent), avg(p_average_mem_usage_percent) by moid, host | rename avg(p_average_cpu_usage_percent) as "cpuUsage",avg(p_average_mem_usage_percent) as "memUsage"| lookup Entity moid AS moid, host AS host | eval procentOverCpu=case((cpuUsage>=85 AND cpuUsage<90)  ,"1",1=1,"0")|eval procentOverCpu90=case((cpuUsage>=90 ) ,"1",1=1,"0")|eval procentOverMem=case((memUsage>=85 AND memUsage<90) ,"1",1=1,"0")|eval procentOverMem90=case((memUsage>90),"1",1=1,"0")|search lowername!=hybseaprd*|append [ |inputlookup Entity  | eval procentOverCpu=0, procentOverMem=0 ,procentOverCpu90=0 ,procentOverMem90=0]
0 Karma


Do you mean too many alerts by 'fake' alerts? Have you set your throttling options correctly in the alert set up?

0 Karma
Get Updates on the Splunk Community!

Dashboard Studio Challenge - Learn New Tricks, Showcase Your Skills, and Win Prizes!

Reimagine what you can do with your dashboards. Dashboard Studio is Splunk’s newest dashboard builder to ...

Introducing Edge Processor: Next Gen Data Transformation

We get it - not only can it take a lot of time, money and resources to get data into Splunk, but it also takes ...

Take the 2021 Splunk Career Survey for $50 in Amazon Cash

Help us learn about how Splunk has impacted your career by taking the 2021 Splunk Career Survey. Last year’s ...