Monitoring Splunk

Monitoring 15% drop in logins with delta

hornettj
New Member

Hi bit of background, I am trying to monitor a 15% drop in logins using the delta command at the moment over Last 15mins

I am using the below search as my test:
index=*_XXXX_app AND (/security/session) | eval call=case(uri like "/security/session%","Login") | timechart count span=5m | delta count as difference | eval percdif=round(abs(difference/count)*100,0)

My Final Search which I will use to create an alert is:
index=*_XXXX_app AND (/security/session) | eval call=case(uri like "/security/session%","Login") | timechart count span=5m | delta count as difference | eval percdif=round(abs(difference/count)*100,0) | where percdif>=15 AND difference<0 | eval mesg="Suspected Service Impact 15 Percent drop in Traffic" | table _time mesg

The problem I have is it keeps triggering against the last minute

example if I run it I get

_time count difference percdif
2016-02-14 08:45:00 258

2016-02-14 08:50:00 377 119 32
2016-02-14 08:55:00 358 -19 5
2016-02-14 09:00:00 15 -343 2287

It does not like the first and last minute of data, do I need to find away to get it to ignore the last minute?

Tags (1)
0 Karma

renjith_nair
Legend

Try the option partial=false in timechart to exclude the partial buckets(beginning and end)

Happy Splunking!
0 Karma

hornettj
New Member

Unfortunately that still did not work

I think I found a work around by using a relative searc
Relative:
Earliest = 12min “Beginning of minute”
Latest = “Beginning of current minute”

So far its behaving

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...