Hello I am a newbie on Splunk. I need to create an alert if #1 IP generated >2X of the #2 IP
and this is my search
sourcetype=csv | top sipAddress | head 2
sipAddress count
10.10.9.23 200
12.12.3.4 50
basically I will need to have first one divided by second if > 2 then I could put in my alert to send to customer.
Please help
Thanks
Try something like this :
sourcetype=csv | top limit=2 sipAddress |streamstats first(count) as count_B window=1 global=f current=f | tail 1 |eval count_ratio=count_B/count | table count_ratio
Try something like this :
sourcetype=csv | top limit=2 sipAddress |streamstats first(count) as count_B window=1 global=f current=f | tail 1 |eval count_ratio=count_B/count | table count_ratio