@rakeshreddy1230, can you try below query? You can set alert if result is more than zero. index=AlwaysUseIndex service_name=MyService request_host=something.com "parameter_check"
| rex field=route "^(?<route>.*)\?"
| eval pTime = total_time
| eval TimeFrames = case(pTime<=1000, "0-1", pTime>1000 AND pTime<=3000, "1-3", pTime>3000 AND pTime<=5000, "3-5", pTime>5000 AND pTime<=8000, "5-8", pTime>8000, ">8", pTime>20000, "ReallyBad")
| stats count as CallVolume by route, TimeFrames
| eventstats sum(CallVolume) as Total by route
| eval Percentage=round((CallVolume/Total)*100,2)
| stats max(Total) as Total max(Percentage) as Percentage by route TimeFrames
| where Percentage > 0.2 AND (TimeFrames=">8" OR TimeFrames="ReallyBad")
... View more