Creating Meaningful Alerts


1 comment

  • Avatar
    Mario Sanchez

    Want more? Here's another example of how to use this same query template to track percentage of errors.


     _sourceCategory= mysourcecategory 
    | timeslice 1h
    | if (!isempty(error),1,0) as errorcount
    | if (isempty(error),1,0) as noerror
    | sum (errorcount) as errorcount,
    sum(noerror) as noerror by _timeslice
    | (errorcount/(noerror))*100 as percentage_of_errors
    | fields - errorcount, noerror
    | sort by _timeslice, percentage_of_errors
    Comment actions Permalink

Please sign in to leave a comment.