You can use the extract fields to create a separate field for that if you see it reoccurring in multiple events.
https://docs.splunk.com/Documentation/Splunk/7.2.6/Knowledge/ExtractfieldsinteractivelywithIFX
After you get it extracted you can create an alert when that field is greater than your number.
Hope that helps.
Alspeedo
... View more