I have a search query that outputs the count of the event for all the host (i.e., | stats count by host)
Now if the count is greater than 5,(for say host 1 and host 2 together gives more than 5 counts),an alert has to be triggered..
Let me know how..
TIA
Perhaps this will fill the need. Search for this:
| stats count by host
| addcoltotals labelfield=host label=TOTAL count
then have the alert trigger using the Custom setting:
search (host=TOTAL AND count > 5)
| stats count by host
| stats sum(count) as count
| where count > 5
Thanks @richgalloway for the suggestion..
But what i would want is,to have host wise count in the alert mail..and the alert has to be triggered if the overall count is greater than 5
Perhaps this will fill the need. Search for this:
| stats count by host
| addcoltotals labelfield=host label=TOTAL count
then have the alert trigger using the Custom setting:
search (host=TOTAL AND count > 5)
You could try this
| stats count by host
| streamstats sum(count) as total_count
| where total_count > 5
r. Ismo