<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to create patterns in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-create-patterns/m-p/335939#M40011</link>
    <description>&lt;P&gt;Thank you for your response. &lt;/P&gt;

&lt;P&gt;I have been working on these commands past week but not able to find a proper solution. I can only work on single field but here, if i search a file_name that  should be show whole patterns of all fields and if the file_name has missed or low probability then it should show on anomalies list. &lt;/P&gt;

&lt;P&gt;NOTE: I want to find out anomalies from the patterns of the file&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 17:51:28 GMT</pubDate>
    <dc:creator>chandana204</dc:creator>
    <dc:date>2020-09-29T17:51:28Z</dc:date>
    <item>
      <title>How to create patterns</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-create-patterns/m-p/335937#M40009</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
 I am working on a data which contained different types of fields. I wanted to create patterns using these fields. &lt;BR /&gt;
Ex: the data is as below&lt;BR /&gt;
process= "processed"&lt;BR /&gt;
process="send"&lt;BR /&gt;
transfer="transferred"&lt;BR /&gt;
error="fatal"&lt;/P&gt;

&lt;P&gt;the above data flow is : Processed --&amp;gt; send --&amp;gt; transferred ( if the file is not able to make send/transferred that will reflect on error field )&lt;/P&gt;

&lt;P&gt;My question is here, If i search for a file_name this total pattern should be show w.r.t timestamp. How can i create patterns using splunk tool. I am wondering does splunk tool has that much capability to create new patterns and find anomalies from these patterns?&lt;/P&gt;

&lt;P&gt;Appreciate for your help&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Chandana &lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2018 17:58:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-create-patterns/m-p/335937#M40009</guid>
      <dc:creator>chandana204</dc:creator>
      <dc:date>2018-01-26T17:58:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to create patterns</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-create-patterns/m-p/335938#M40010</link>
      <description>&lt;P&gt;Splunk SPL provides several methods for anomaly detection. Refer to anomalydetection and related commands in Splunk Documentation: &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/ListOfSearchCommands"&gt;http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/ListOfSearchCommands&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Also refer to Advanced Statistics documentation: &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Search/Aboutadvancedstatistics"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Search/Aboutadvancedstatistics&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;In your case you should apply &lt;CODE&gt;prediction&lt;/CODE&gt; and &lt;CODE&gt;outlier&lt;/CODE&gt; for all series "processed", "send", "transferred" and "fatal". You can also refer to &lt;A href="https://splunkbase.splunk.com/app/2890/"&gt;Splunk Machine Learning Toolkit&lt;/A&gt; for this.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2018 18:12:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-create-patterns/m-p/335938#M40010</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2018-01-26T18:12:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to create patterns</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-create-patterns/m-p/335939#M40011</link>
      <description>&lt;P&gt;Thank you for your response. &lt;/P&gt;

&lt;P&gt;I have been working on these commands past week but not able to find a proper solution. I can only work on single field but here, if i search a file_name that  should be show whole patterns of all fields and if the file_name has missed or low probability then it should show on anomalies list. &lt;/P&gt;

&lt;P&gt;NOTE: I want to find out anomalies from the patterns of the file&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 17:51:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-create-patterns/m-p/335939#M40011</guid>
      <dc:creator>chandana204</dc:creator>
      <dc:date>2020-09-29T17:51:28Z</dc:date>
    </item>
  </channel>
</rss>

