I want to be able to detect unnormal spikes in the number of certain messages. for example, in the screenshot below the normal behavior is between 100-15,000 messages in 1 hour, so I used this query but I want to modify it so it will alert (message_indicator=1) if the total alert are around 20K. How can I do that? I used this:
AND !"with 0 errors")
AND !"\"error\": null,")
AND !"response: code = 200,"
|count as message by _timeslice
|outlier message window=10,threshold=10,consecutive=2
Please sign in to leave a comment.