Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Need to compare the last hour values of the fields with current one hour

$
0
0
Hi, We are monitoring the transaction count. I need to verify the results of last one hour, if there is any decrease in the count the alert needs to be generated. For example : 7 AM to 8 AM - transaction count with fields 8 AM to 9 AM - I need to verify the fields values with 7AM to 8AM field values. If the count get decreased alerts needs to notified. How to write the search for this scenario.? Please suggest

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>