Alerting

Alert Based on the output results

kirangurram
Explorer

Hello Experts ,
I have a splunk query which is giving me average response time using the filed "process_time".
I want to create an Alert when output of this query is > 2 seconds. Please advice , how I could setup this alert.
I tried multiple options they didint work. I tried to add | where process_time > 2. but this option didnt work.

query | stats avg(process_time)

Output :
avg(process_time)
0.07894736842105263

0 Karma
1 Solution

harsmarvania57
Ultra Champion

Hi,

Please try below

<yourSearch> 
| stats avg(process_time) as avg_process_time
| where avg_process_time > 2

View solution in original post

harsmarvania57
Ultra Champion

Hi,

Please try below

<yourSearch> 
| stats avg(process_time) as avg_process_time
| where avg_process_time > 2

kirangurram
Explorer

This works like a charm ... Thanks

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@kirangurram
try this

query | stats avg(process_time) as process_time | where process_time > 2

kirangurram
Explorer

This works like a charm ... Thanks

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...