<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Anomaly Detection on a Key list of fields in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Anomaly-Detection-on-a-Key-list-of-fields/m-p/537162#M90037</link>
    <description>&lt;P&gt;I did check in MLTK thoroughly now, but nothing inbuilt for Splunk own sourcetypes/eventtypes/fields&lt;/P&gt;&lt;P&gt;So it is a generic which I've to build up. hopefully will see if anyone else have built-up on such deviations for Splunk's own fields&lt;/P&gt;</description>
    <pubDate>Tue, 26 Jan 2021 08:23:36 GMT</pubDate>
    <dc:creator>koshyk</dc:creator>
    <dc:date>2021-01-26T08:23:36Z</dc:date>
    <item>
      <title>Anomaly Detection on a Key list of fields</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Anomaly-Detection-on-a-Key-list-of-fields/m-p/536206#M89895</link>
      <description>&lt;P&gt;Our system currently has grown over time with 1000's of enrichments, TA and custom apps. We were planning to upgrade Splunk to another version and wanted to do as much testing automated&lt;/P&gt;&lt;P&gt;So i've developed plan to pump Live data pre &amp;amp; post change in TEST machine thus detecting the important fields, eventtypes, tags are working correctly. But this measurement is done manually&lt;/P&gt;&lt;P&gt;Is there an easy way or module to detect such anomalies or divergence if we give a set of "fields" it should detect for?&lt;/P&gt;&lt;P&gt;For example, what i'm looking for is&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;# set of key-fields
user
eventtypes
tags
host&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to detect if the values of these `key-fields` have dramatically changed between two cycles (or dates), thus we can say a particular TA or upgrade caused to break those fields&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jan 2021 13:18:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Anomaly-Detection-on-a-Key-list-of-fields/m-p/536206#M89895</guid>
      <dc:creator>koshyk</dc:creator>
      <dc:date>2021-01-18T13:18:58Z</dc:date>
    </item>
    <item>
      <title>Re: Anomaly Detection on a Key list of fields</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Anomaly-Detection-on-a-Key-list-of-fields/m-p/536210#M89896</link>
      <description>&lt;P&gt;Machine Learning Toolkit (MLTK) might give you what you need, although you will still have to invest some time developing and evaluating your models before they can reliably be used to detect anomalies.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jan 2021 13:38:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Anomaly-Detection-on-a-Key-list-of-fields/m-p/536210#M89896</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-01-18T13:38:07Z</dc:date>
    </item>
    <item>
      <title>Re: Anomaly Detection on a Key list of fields</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Anomaly-Detection-on-a-Key-list-of-fields/m-p/537162#M90037</link>
      <description>&lt;P&gt;I did check in MLTK thoroughly now, but nothing inbuilt for Splunk own sourcetypes/eventtypes/fields&lt;/P&gt;&lt;P&gt;So it is a generic which I've to build up. hopefully will see if anyone else have built-up on such deviations for Splunk's own fields&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jan 2021 08:23:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Anomaly-Detection-on-a-Key-list-of-fields/m-p/537162#M90037</guid>
      <dc:creator>koshyk</dc:creator>
      <dc:date>2021-01-26T08:23:36Z</dc:date>
    </item>
  </channel>
</rss>

