Splunk Search
Highlighted

How to alert based off the last reported number in a stats count

Contributor

How to alert based off the last reported number in a time chart. I want to alert based on a comparison of the last two numbers where if it that value grew more than x%, I want it to alert.

0 Karma
Highlighted

Re: How to alert based off the last reported number in a stats count

SplunkTrust
SplunkTrust

Could you provide more information on your current outputs and expected output? (The title says stats and the question says timechart ) Also share you current queries.

0 Karma
Highlighted

Re: How to alert based off the last reported number in a stats count

Esteemed Legend

add this:

 | tail 2 | reverse | autoregress count | eval pct_increase=100 * (count - count_p1)/count | where pct_increase > X

View solution in original post

Highlighted

Re: How to alert based off the last reported number in a stats count

Contributor

so this is great however the pctincrease (i renamed it to pctdiff) is not putting a decimal so for instance
count countp1 pctdiff
18.32 10.25 807
pct_diff should be 8.07

i fixed it by adding a decimal
| eval pctincrease=1.00 * (count - countp1)/count | where pct_increase > X

thanks again i will be suing this a lot!

0 Karma