Hi All,
these are the logger info counts which are generated in splunk
Total numner where inds-a 20 Total numner where inds-b 30 Total numner where inds-c 40 Total numner where inds-d 50
i need to create a alert based on inds-c percentage
if inds-c is greater than 10% it should create a alert
below is the search query i am trying but it has some issue with the rex part ,any suggestions
index=abc log_severity=INFO OR WARN appname=doc country=ind earlies=@d |rex "Total Number where inds-c (?<counts>\d+)" |rex "Total Number where inds-* (?<Allcounts>\d+)" eval percentage=((counts/Allcounts)*100) where percentage>=10
... View more