<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Difference between anomalies and anomalousvalue in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Difference-between-anomalies-and-anomalousvalue/m-p/106847#M27800</link>
    <description>&lt;P&gt;anomalousvalue actually only analyzes one field at a time, but it you can apply it to any arbitrary set of fields.  anomalousvalue has several modes.  In the summary mode, it will just emit an report of the various fields that exist and their behavior with regard to having values that may be anomalous.&lt;/P&gt;</description>
    <pubDate>Mon, 02 Apr 2012 23:06:34 GMT</pubDate>
    <dc:creator>steveyz</dc:creator>
    <dc:date>2012-04-02T23:06:34Z</dc:date>
    <item>
      <title>Difference between anomalies and anomalousvalue</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Difference-between-anomalies-and-anomalousvalue/m-p/106846#M27799</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Can anyone explain the difference between anomalies and anomalousvalue?  From the search reference, it looks like anomalies operates on a single field and is context-sensitive (i.e. looks at the surrounding X events to see if the current event is unusual), while anomalousvalue looks at the combination of all fields over the entire time range.  If that's wrong, please correct me.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Apr 2012 15:23:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Difference-between-anomalies-and-anomalousvalue/m-p/106846#M27799</guid>
      <dc:creator>cphair</dc:creator>
      <dc:date>2012-04-02T15:23:32Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between anomalies and anomalousvalue</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Difference-between-anomalies-and-anomalousvalue/m-p/106847#M27800</link>
      <description>&lt;P&gt;anomalousvalue actually only analyzes one field at a time, but it you can apply it to any arbitrary set of fields.  anomalousvalue has several modes.  In the summary mode, it will just emit an report of the various fields that exist and their behavior with regard to having values that may be anomalous.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Apr 2012 23:06:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Difference-between-anomalies-and-anomalousvalue/m-p/106847#M27800</guid>
      <dc:creator>steveyz</dc:creator>
      <dc:date>2012-04-02T23:06:34Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between anomalies and anomalousvalue</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Difference-between-anomalies-and-anomalousvalue/m-p/106848#M27801</link>
      <description>&lt;P&gt;So if had data that had host and event fields, and I ran anomalousvalue action=filter host,event ... would I get a set of results that listed the unusual hosts, or the unusual events, or the rarest host/event combinations?  For that matter, what's the difference between anomalous and rare?&lt;/P&gt;

&lt;P&gt;Am I correct that anomalies looks at the immediate surrounding events and anomalousvalue looks at everything in the range?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Apr 2012 13:57:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Difference-between-anomalies-and-anomalousvalue/m-p/106848#M27801</guid>
      <dc:creator>cphair</dc:creator>
      <dc:date>2012-04-03T13:57:33Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between anomalies and anomalousvalue</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Difference-between-anomalies-and-anomalousvalue/m-p/106849#M27802</link>
      <description>&lt;P&gt;@steveyz -- not sure if you got a notification about my previous comment...&lt;/P&gt;</description>
      <pubDate>Thu, 05 Apr 2012 13:30:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Difference-between-anomalies-and-anomalousvalue/m-p/106849#M27802</guid>
      <dc:creator>cphair</dc:creator>
      <dc:date>2012-04-05T13:30:03Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between anomalies and anomalousvalue</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Difference-between-anomalies-and-anomalousvalue/m-p/106850#M27803</link>
      <description>&lt;P&gt;You would get a list of results that had either unusual hosts, unusual events, or both.&lt;/P&gt;

&lt;P&gt;Rare is just the converse of top and is purely a reporting command.  Rare doesn't necessarily mean anomalous if you you have a lot of rare values.  anomalousvalue considers the distribution of values when deciding if something is anomalous or not.  Also for numerical fields, anomalousvalue uses average and variance/stdev to determine what is anomalous.&lt;/P&gt;

&lt;P&gt;Anomalousvalue does look at the whole event set.  I'm actually not that familar with 'anomalies' so i'm not sure exactly what does not.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Apr 2012 18:02:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Difference-between-anomalies-and-anomalousvalue/m-p/106850#M27803</guid>
      <dc:creator>steveyz</dc:creator>
      <dc:date>2012-04-05T18:02:12Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between anomalies and anomalousvalue</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Difference-between-anomalies-and-anomalousvalue/m-p/106851#M27804</link>
      <description>&lt;P&gt;Perhaps someone might find this useful:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://www.prelert.com/blog/anomaly-detective-vs-splunks-anomalies-command-what-is-the-difference/"&gt;http://www.prelert.com/blog/anomaly-detective-vs-splunks-anomalies-command-what-is-the-difference/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2014 14:13:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Difference-between-anomalies-and-anomalousvalue/m-p/106851#M27804</guid>
      <dc:creator>richcollier</dc:creator>
      <dc:date>2014-02-12T14:13:36Z</dc:date>
    </item>
  </channel>
</rss>

