Splunk Search

The alarm time statistics

laiyongmao
Path Finder

Now that there is such a demand, I set up an alarm, when I CPU use rate of more than 90% began to alarm, when the CPU utilization rate of less than 90% is to lift the alarm, the alarm time can be counted a total of ?I don't know Splunk can achieve now, who can help me?

Tags (1)
0 Karma
1 Solution

laiyongmao
Path Finder

The problem has been solved.

View solution in original post

0 Karma

laiyongmao
Path Finder

The problem has been solved.

0 Karma

laiyongmao
Path Finder

thanks jtrucks!
I want to know about an event to another event, such as the int/0 down to int/0 up the time.

13-12-5 上午11时32分59.000秒 int/0 down
13-12-5 上午11时32分57.000秒 int/1 up
13-12-5 上午11时32分56.000秒 int/1 down
13-12-5 上午11时19分29.000秒 int/0 up
13-12-5 上午11时19分29.000秒 int/2 down
13-12-5 上午11时16分47.000秒 int/0 down

thank you very much! What are you chatting tool? How can I contact you?

0 Karma

jtrucks
Splunk Employee
Splunk Employee

Please provide examples of the log events for each of these states: alarm triggered, alarm canceled.

With the format of the logs, we can help you create a transaction based query to answer this question.

--
Jesse Trucks
Minister of Magic
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...