Hello,
I am currently setting up some graphs and I was wondering if there is a simple and flexible way to generate an alert when there is a unusual peak in the graph.
I know I can set up an alert if X events have been found but this is not flexible. Is there a way that Splunk can learn that, for example, on Mondays, there are more events generated so the alert limit should be higher ?
Thank you !
The way I approached this in the past was using a summary index (report acceleration might work too):
I don't have access to my old Splunk instance at the moment so I can't really paste any code or screenshots.
Hope that helps.
Thanks,
J
You could use timewrap
app to compare week-over-week and do a precentage variation that is constant:
Wow, this looks very nice. If you have any other command to compare charts over time, do not hesitate to share it.
The way I approached this in the past was using a summary index (report acceleration might work too):
I don't have access to my old Splunk instance at the moment so I can't really paste any code or screenshots.
Hope that helps.
Thanks,
J
You could also check out the Machine Learning App which features one such use cases explicitly. Check it out if you're interested, I can really recommend it!
Thank you. I will check out this app 🙂