<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Outlier Identifier- help with query in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Outlier-Identifier-help-with-query/m-p/94332#M24310</link>
    <description>&lt;P&gt;Using join to see the changes between the original search and the outlier search, implementing nullif to find the differences, and imbedding he null if in an evalif function fixes the issue, as seen below:&lt;/P&gt;

&lt;P&gt;source="wineventlog:security" EventCode=528 OR EventCode=540 OR EventCode=4624 User_Name!="-" | stats count by User_Name | rename count AS original_count | join type=inner User_Name[search source="wineventlog:security" EventCode=528 OR EventCode=540 OR EventCode=4624 User_Name!="-" | stats count by User_Name | rename count AS outlier_count | outlier type=iqr] | eval Description=if(nullif(outlier_count,original_count)==outlier_count,"outlier","not an outlier") | table User_Name, original_count, outlier_count, Description&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 12:03:28 GMT</pubDate>
    <dc:creator>marywill</dc:creator>
    <dc:date>2020-09-28T12:03:28Z</dc:date>
    <item>
      <title>Outlier Identifier- help with query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Outlier-Identifier-help-with-query/m-p/94331#M24309</link>
      <description>&lt;P&gt;I want to use the outlier function but am having trouble identifying the sources as outlier, this is what I have so far, but using stats and eval together is not working.  Any help and would be greatly appreciated:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;source="wineventlog:security" EventCode=528 OR EventCode=540 OR EventCode=4624 User_Name!="-" | stats count by User_Name| outlier type=iqr | eval Description=case(count&amp;gt;=stats max(count), "outlier", count&amp;lt;stats max(count), "not an outlier") 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 10 Jul 2012 13:22:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Outlier-Identifier-help-with-query/m-p/94331#M24309</guid>
      <dc:creator>marywill</dc:creator>
      <dc:date>2012-07-10T13:22:35Z</dc:date>
    </item>
    <item>
      <title>Re: Outlier Identifier- help with query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Outlier-Identifier-help-with-query/m-p/94332#M24310</link>
      <description>&lt;P&gt;Using join to see the changes between the original search and the outlier search, implementing nullif to find the differences, and imbedding he null if in an evalif function fixes the issue, as seen below:&lt;/P&gt;

&lt;P&gt;source="wineventlog:security" EventCode=528 OR EventCode=540 OR EventCode=4624 User_Name!="-" | stats count by User_Name | rename count AS original_count | join type=inner User_Name[search source="wineventlog:security" EventCode=528 OR EventCode=540 OR EventCode=4624 User_Name!="-" | stats count by User_Name | rename count AS outlier_count | outlier type=iqr] | eval Description=if(nullif(outlier_count,original_count)==outlier_count,"outlier","not an outlier") | table User_Name, original_count, outlier_count, Description&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:03:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Outlier-Identifier-help-with-query/m-p/94332#M24310</guid>
      <dc:creator>marywill</dc:creator>
      <dc:date>2020-09-28T12:03:28Z</dc:date>
    </item>
  </channel>
</rss>

