Knowledge Management

Using Summary Index for deviation

kunadkat
Explorer

How can I accomplish the following:
- Count average number of apache access_common entries span=15m and put it in the summary index(I have to run this everyday)
- Compare realtime data average with 2 weeks ago's summary index data and generate alert if realtime average is 20 percent more summary index data from 14 days ago.

Thanks,

Tags (1)
0 Karma

richcollier
Path Finder
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...