Splunk Search

The alarm time statistics

laiyongmao
Path Finder

Now that there is such a demand, I set up an alarm, when I CPU use rate of more than 90% began to alarm, when the CPU utilization rate of less than 90% is to lift the alarm, the alarm time can be counted a total of ?I don't know Splunk can achieve now, who can help me?

Tags (1)
0 Karma
1 Solution

laiyongmao
Path Finder

The problem has been solved.

View solution in original post

0 Karma

laiyongmao
Path Finder

The problem has been solved.

0 Karma

laiyongmao
Path Finder

thanks jtrucks!
I want to know about an event to another event, such as the int/0 down to int/0 up the time.

13-12-5 上午11时32分59.000秒 int/0 down
13-12-5 上午11时32分57.000秒 int/1 up
13-12-5 上午11时32分56.000秒 int/1 down
13-12-5 上午11时19分29.000秒 int/0 up
13-12-5 上午11时19分29.000秒 int/2 down
13-12-5 上午11时16分47.000秒 int/0 down

thank you very much! What are you chatting tool? How can I contact you?

0 Karma

jtrucks
Splunk Employee
Splunk Employee

Please provide examples of the log events for each of these states: alarm triggered, alarm canceled.

With the format of the logs, we can help you create a transaction based query to answer this question.

--
Jesse Trucks
Minister of Magic
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...