How can I accomplish the following:
- Count average number of apache access_common entries span=15m and put it in the summary index(I have to run this everyday)
- Compare realtime data average with 2 weeks ago's summary index data and generate alert if realtime average is 20 percent more summary index data from 14 days ago.
Thanks,
This sounds similar to the question posed here: http://splunk-base.splunk.com/answers/60640/alerting-based-on-deviation-on-multi-dimensional-data