I've set up a simple search for flapping interfaces on our switches, looks like so:
LINEPROTO-5-UPDOWN: Line protocol on Interface changed state to | stats count by host
What I'd like to do is get an alert using a conditional ... stats count by host > 5 in fifteen minutes or something like that. When I try this out it returns no data:
LINEPROTO-5-UPDOWN: Line protocol on Interface changed state to | stats count by host > 5
How do I get from there to where I want to be?
LINEPROTO-5-UPDOWN: Line protocol on Interface changed state to | stats count by host | where count > 5
LINEPROTO-5-UPDOWN: Line protocol on Interface changed state to | stats count by host | where count > 5
One would think I could have tried that myself but I've apparently got too many hats on today to be any good at one thing. Thanks!
sorry, should be count > 5
, not host
. editing to fix.
It looks like it should work but still "No results found" which is strange, when I take out the where clause, there are a couple values above five.