How would I set an alarm from a _sourceName value that is returning a 21% message and set an alarm when that message is greater= to 85%, send an email?


1 comment

  • Avatar
    Kelly Hamm
    Hi, assuming this is the intact multiline message you've posted: | parse "message=*%" as perc | where perc>=85 | count by _sourceName set that up in a scheduled search, choose your timeframes and recipients, and you should be good to go.
    Comment actions Permalink

Please sign in to leave a comment.