sourcetype="access_test" -------------- |
eval AllenPercentage=(Allen_hits/Total_hits)*100 as AllenPercentage |
eval RcdnPercentage=(Rcdn_hits/Total_hits)*100 as RcdnPercentage |
I would like to set a custom alert if RcdnPercentage reaches to 80% and AllenPercentage reaches to 20%
Add this to the end of your search:
| where RcdnPercentage >= .8 AND AllenPercentage >= .2
Then set the Alter Condition to Number of Results > 0.
That should work