Hi all, I'm currently trying to use splunk to create an alert for the following scenario: I have a search that tell's me the number os rows and partitions a data pipeline ingested, so basically i already extract the following fields: - Table Name - Number of partitions - Number of rows I also have a dashboard that shows me the timechart of the number of partitions and rows across different executions during the time. What i need in this example, is to have an alert that get triggered when the number of the partitions or rows have more than a specified % of difference between executions. So in this example, the executions 1 and 2 have a low difference between then, but the execution 3 is clearly an outlier, that should be alerted. Execution 1: table_name = table_1 num_part = 12 num_rows = 1400 Execution 2: table_name = table_1 num_part = 10 num_rows = 1000 Execution 3: table_name = table_1 num_part = 10000 num_rows = 100000000 Any sugestions on how i can do it?
... View more