Conditional Alerting in SumoLogic

Comments

3 comments

  • Avatar
    Caleb Fogleman
    Krishna, You should be able to do this by modifying your query in one of these two ways: _source=elb_east ........... | acheived_percentage < 99.5 ? "SLA Breach" :"OK" as status | where status="SLA Breach" OR _source=elb_east ........... | where acheived_percentage < 99.5 Either of these should only produce results in the event of a failure, and will not list any results as OK. Then, you should be able to schedule your search to alert on > 0 results. I hope this helps! Thanks, Caleb F.
    0
    Comment actions Permalink
  • Avatar
    Krishna Susarla
    Thank you Caleb. It works. :) ThanksKrishna
    0
    Comment actions Permalink
  • Avatar
    Unknown

    I want to add email alert from sumologic if Log size in panel crosses 15GB. Please help me to add this email alert with threshold value 15gb. 

    0
    Comment actions Permalink

Please sign in to leave a comment.