Sudden Increase in Source Volume

This alert is triggered when there is a 60% increase in data volume compared to a prior window.

General Configuration

FieldValue
NameSudden increase in source volume.
DescriptionTriggers when a source volume increases by 60% compared to prior window.

Evaluation and Condition Configuration

FieldValue
OperationCustom
Window TypeTumbling
Window Duration (minutes)30
Group by Field Paths.source
OperationCustom
Window TypeTumbling
Window Duration (minutes)30
Conditional Statementif (.log_volumepercent_change_greater_or_equal 60)
Event Timestamp.timestamp

Custom Script

Bash
Copy
Type to search, ESC to discard
Type to search, ESC to discard
Type to search, ESC to discard
  Last updated