payload Search with key value


1 comment

  • Avatar
    Rick Jury

    add this to your search:

    "200 OK YMKT UAT"


    to count total add:

    | count


    to count over time add:

    | count by _timeslice


    once you the aggregate count in your query you will find an add to dashboard button will appear so you an add it as a panel.

    To schedule an alert to say email or webhook to slack you can follow the instructions here in detail:


    In your case I'd suggest you add a line like this say if you want to alert only when it's > 100

    | where _count > 100


    Then when you save the alert search you can use criteria to only send alert when number of events is > 0. 

    Comment actions Permalink

Please sign in to leave a comment.