I'm looking to use a watcher that does the following:
Compare the error/succes rate of the last 5 minutes to the last 10 minutes. if there is a drop or spike an action is fired. (based on https://www.elastic.co/videos/watcher-lab-creating-alerts-with-dynamic-threshold)
I've got an index that is populated with Apache logs.
I want to know if the percentage of 4xx response codes spikes during the day.
Does anyone have an example that can get me started? The video puts me on the right track but I am stuck.
Any help would be appreciated