Closed GoogleCodeExporter closed 8 years ago
This is possible right now using a combination of the sum and has transforms.
Let's say that you want to alert on the keyword "evil" if it shows up in the
logs more than five times. Here's the query to put in as an alert:
evil | count(timestamp) | has(5)
As long as "evil" shows up in five separate seconds within that minute, then
you'll get an alert. You could also make it less than a certain amount by
setting the operator as the second parameter to has:
evil | count(timestamp) | has(5,<)
That would mean only alert if there are fewer than five distinct seconds having
a hit for "evil."
Does that fulfill your needs?
Original comment by mchol...@gmail.com
on 30 Apr 2013 at 3:13
So I would put the "evil | count(timestamp) | has(5) within the parameters in
the "Schedule or Alert" option?
Original comment by andrew.w...@gmail.com
on 30 Apr 2013 at 6:08
Yes, that's correct. If there aren't five hits, then there are zero results
returned and the alert won't fire.
Original comment by mchol...@gmail.com
on 1 May 2013 at 2:13
Great! Thanks for the timely and helpful response.
Original comment by andrew.w...@gmail.com
on 1 May 2013 at 6:30
Original comment by mchol...@gmail.com
on 1 May 2013 at 10:37
Original issue reported on code.google.com by
andrew.w...@gmail.com
on 29 Apr 2013 at 11:58