<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Anomaly Detection Feature in Service for ITSI? in Splunk ITSI</title>
    <link>https://community.splunk.com/t5/Splunk-ITSI/Anomaly-Detection-Feature-in-Service-for-ITSI/m-p/499065#M2010</link>
    <description>&lt;P&gt;Thanks for your time.&lt;/P&gt;

&lt;P&gt;Im using Trending AD. what I need is . If you use the feature it shows RED points on graph to indicate its a anomaly. How can I get complete information using Splunk Query ? I cant manually get to any file to review the information.&lt;/P&gt;

&lt;P&gt;for example I have a KPI and I want to know whats its Health score. then I can use index=ITSI_Summary and kpi name to get the score value .  by running a query, I need similar setup.&lt;/P&gt;

&lt;P&gt;Like I said I need to avoid certain steps in a process when model detects anomaly.&lt;/P&gt;

&lt;P&gt;Thanks Satya&lt;/P&gt;</description>
    <pubDate>Tue, 04 Feb 2020 09:19:32 GMT</pubDate>
    <dc:creator>satyab</dc:creator>
    <dc:date>2020-02-04T09:19:32Z</dc:date>
    <item>
      <title>Anomaly Detection Feature in Service for ITSI?</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/Anomaly-Detection-Feature-in-Service-for-ITSI/m-p/499062#M2007</link>
      <description>&lt;P&gt;Hello ALL,&lt;BR /&gt;I would like to know is &lt;STRONG&gt;where are anomaly detection Information is stored in ITSI?&lt;/STRONG&gt;, I mean any specific Index bucket? or is that a Black Box for us?.I know it is going into "Episode review" but that will not help me . I need to pro grammatically get this information just like I get KPI score from ITSI-Summary. As I need to stop my system alerting when it detects Anomaly.&lt;/P&gt;
&lt;P&gt;Secondly, where can I find detailed information about &lt;STRONG&gt;how it is detecting Anomaly&lt;/STRONG&gt;?As, I was wondering is there an option to change any setting?&lt;/P&gt;
&lt;P&gt;Thanks&lt;BR /&gt;Satya&lt;/P&gt;</description>
      <pubDate>Sun, 07 Jun 2020 00:40:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/Anomaly-Detection-Feature-in-Service-for-ITSI/m-p/499062#M2007</guid>
      <dc:creator>satyab</dc:creator>
      <dc:date>2020-06-07T00:40:53Z</dc:date>
    </item>
    <item>
      <title>Re: Anomaly Detection Feature in Service for ITSI?</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/Anomaly-Detection-Feature-in-Service-for-ITSI/m-p/499063#M2008</link>
      <description>&lt;P&gt;Hi Satya, this documentation might help to answer your second question: &lt;A href="https://docs.splunk.com/Documentation/ITSI/latest/Configure/Enableanomalydetection"&gt;https://docs.splunk.com/Documentation/ITSI/latest/Configure/Enableanomalydetection&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2020 18:54:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/Anomaly-Detection-Feature-in-Service-for-ITSI/m-p/499063#M2008</guid>
      <dc:creator>esnyder_splunk</dc:creator>
      <dc:date>2020-01-30T18:54:00Z</dc:date>
    </item>
    <item>
      <title>Re: Anomaly Detection Feature in Service for ITSI?</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/Anomaly-Detection-Feature-in-Service-for-ITSI/m-p/499064#M2009</link>
      <description>&lt;P&gt;Are you using cohesive AD or trending AD? This is stored in the kv-store. You can configure this in the &lt;CODE&gt;mad.conf&lt;/CODE&gt; settings within the SA-ITSI-MetricAD app. &lt;/P&gt;

&lt;P&gt;What exactly are you looking for?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2020 19:25:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/Anomaly-Detection-Feature-in-Service-for-ITSI/m-p/499064#M2009</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2020-01-30T19:25:33Z</dc:date>
    </item>
    <item>
      <title>Re: Anomaly Detection Feature in Service for ITSI?</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/Anomaly-Detection-Feature-in-Service-for-ITSI/m-p/499065#M2010</link>
      <description>&lt;P&gt;Thanks for your time.&lt;/P&gt;

&lt;P&gt;Im using Trending AD. what I need is . If you use the feature it shows RED points on graph to indicate its a anomaly. How can I get complete information using Splunk Query ? I cant manually get to any file to review the information.&lt;/P&gt;

&lt;P&gt;for example I have a KPI and I want to know whats its Health score. then I can use index=ITSI_Summary and kpi name to get the score value .  by running a query, I need similar setup.&lt;/P&gt;

&lt;P&gt;Like I said I need to avoid certain steps in a process when model detects anomaly.&lt;/P&gt;

&lt;P&gt;Thanks Satya&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2020 09:19:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/Anomaly-Detection-Feature-in-Service-for-ITSI/m-p/499065#M2010</guid>
      <dc:creator>satyab</dc:creator>
      <dc:date>2020-02-04T09:19:32Z</dc:date>
    </item>
    <item>
      <title>Re: Anomaly Detection Feature in Service for ITSI?</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/Anomaly-Detection-Feature-in-Service-for-ITSI/m-p/499066#M2011</link>
      <description>&lt;P&gt;Thanks this is general setup document. thats it what I am looking for.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2020 09:20:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/Anomaly-Detection-Feature-in-Service-for-ITSI/m-p/499066#M2011</guid>
      <dc:creator>satyab</dc:creator>
      <dc:date>2020-02-04T09:20:42Z</dc:date>
    </item>
    <item>
      <title>Re: Anomaly Detection Feature in Service for ITSI?</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/Anomaly-Detection-Feature-in-Service-for-ITSI/m-p/499067#M2012</link>
      <description>&lt;P&gt;This is a limitation of the product. As far as I know, it does NOT write the anomalous behavior to the itsi_summary index. I've been a big advocate for doing adaptive thresholding on a per entity basis which WOULD write to the itsi summary index as it does with the aggregate values. I've also built my own in-house solution of this which works on thousands of entities per KPI. It's much faster than the current AT with a lighter footprint. So my suggestion is to wait for it to become available and keep asking the product team for it&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2020 17:58:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/Anomaly-Detection-Feature-in-Service-for-ITSI/m-p/499067#M2012</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2020-02-04T17:58:03Z</dc:date>
    </item>
    <item>
      <title>Re: Anomaly Detection Feature in Service for ITSI?</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/Anomaly-Detection-Feature-in-Service-for-ITSI/m-p/499068#M2013</link>
      <description>&lt;P&gt;Configuration:&lt;BR /&gt;
- KPI object in the service object&lt;BR /&gt;
- A collection in SA-ITSI-MetricAD&lt;BR /&gt;
- Savedsearches.conf in SA-ITSI-MetricAD&lt;/P&gt;

&lt;P&gt;Computational Middle Work:&lt;BR /&gt;
- there is an index for it called anomaly or something defined in SA-ITSI-MetricAD&lt;/P&gt;

&lt;P&gt;Final resultant Anomaly:&lt;BR /&gt;
- it's a notable event like any other, so tracked alerts index and then the episodes index&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2020 00:12:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/Anomaly-Detection-Feature-in-Service-for-ITSI/m-p/499068#M2013</guid>
      <dc:creator>esnyder_splunk</dc:creator>
      <dc:date>2020-02-06T00:12:18Z</dc:date>
    </item>
    <item>
      <title>Re: Anomaly Detection Feature in Service for ITSI?</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/Anomaly-Detection-Feature-in-Service-for-ITSI/m-p/499069#M2014</link>
      <description>&lt;P&gt;Thanks you. Sure will do.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2020 09:37:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/Anomaly-Detection-Feature-in-Service-for-ITSI/m-p/499069#M2014</guid>
      <dc:creator>satyab</dc:creator>
      <dc:date>2020-02-06T09:37:45Z</dc:date>
    </item>
  </channel>
</rss>

