outlier alerts

Comments

1 comment

  • Official comment
    Avatar
    Matt Sullivan

    if by total, you mean within the timeslice, and you are only alerting based on the count, no longer using outlier's standard deviation approach, just replace the outlier line with

    | where _count > 20000

    and then your alert condition is if there are > 0 results.

    if you really mean total over the entire time range of query, rather than each timeslice within, drop the timeslice line and don't include by _timeslice in the count.

    p.s. the kv auto I don't think is doing anything in above so can drop that too.

Please sign in to leave a comment.