Alerting

alert when an increase of indexed data more than 10%

nikolab
Explorer

Hi
I know that you have been answered before something similarly, but..I need for my managemant set alert on splunk when indexed volume data are 10% higher than daily average.
We have a problems to detect which of ours sourcetypes, indexes or sources produce a high volume of data, so I need alert to notify me by email where is a problem.

thanks in advance

Nikola

1 Solution

mreynov_splunk
Splunk Employee
Splunk Employee

In this answer you can get the daily volume: https://answers.splunk.com/answers/29415/daily-index-volume-by-sourcetype.html
You can run the same search for the day before and use eval to compare

View solution in original post

mreynov_splunk
Splunk Employee
Splunk Employee

In this answer you can get the daily volume: https://answers.splunk.com/answers/29415/daily-index-volume-by-sourcetype.html
You can run the same search for the day before and use eval to compare

nikolab
Explorer

Thanks..it is ok, and works fine. Now I can compare index or sourcetype with day or week before.
I have just one question...is it possible that splunk tell me which host ( and we have hundreds of them ) produces the greatest amount of data?
It would be very useful for quick response the problem.

thanks

Nikola

0 Karma

nikolab
Explorer

And, alert is not a problem..my problem is good search which will give to me the comparison of volume data..avg and 10% higher

thanks

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...