<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Standard Deviation of Timechart in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Standard-Deviation-of-Timechart/m-p/114119#M30132</link>
    <description>&lt;P&gt;I'm working on a chart which will map a baseline of existing data. The search I am currently using is as follows.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;sourcetype=pan_threat severity!=informational | eventstats count as totalcount | eval threshold=(totalcount/25) | timechart span=1h count, first(threshold) as "Maximum Threshold"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;That works great for getting the average charting. I now also want to take the Standard Deviation of the timechart of the count, and map that as well. Anyone have any idea how to do that? I've tried a second eventstats, which throws me back some very weird standard deviations on the data itself.&lt;/P&gt;</description>
    <pubDate>Thu, 24 Oct 2013 19:09:39 GMT</pubDate>
    <dc:creator>tfitzgerald15</dc:creator>
    <dc:date>2013-10-24T19:09:39Z</dc:date>
    <item>
      <title>Standard Deviation of Timechart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Standard-Deviation-of-Timechart/m-p/114119#M30132</link>
      <description>&lt;P&gt;I'm working on a chart which will map a baseline of existing data. The search I am currently using is as follows.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;sourcetype=pan_threat severity!=informational | eventstats count as totalcount | eval threshold=(totalcount/25) | timechart span=1h count, first(threshold) as "Maximum Threshold"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;That works great for getting the average charting. I now also want to take the Standard Deviation of the timechart of the count, and map that as well. Anyone have any idea how to do that? I've tried a second eventstats, which throws me back some very weird standard deviations on the data itself.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2013 19:09:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Standard-Deviation-of-Timechart/m-p/114119#M30132</guid>
      <dc:creator>tfitzgerald15</dc:creator>
      <dc:date>2013-10-24T19:09:39Z</dc:date>
    </item>
    <item>
      <title>Re: Standard Deviation of Timechart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Standard-Deviation-of-Timechart/m-p/114120#M30133</link>
      <description>&lt;P&gt;Of course this is going to sound like a shameless plug, but honestly, the easiest way to do this is with the Prelert Anomaly Detective app.&lt;/P&gt;

&lt;P&gt;Using the QuickMode feature, you can literally put this search in:&lt;/P&gt;

&lt;P&gt;sourcetype=pan_threat severity!=informational | timechart count &lt;/P&gt;

&lt;P&gt;and Anomaly Detective will automatically take care of baselining the normal occurrence rate and will offer you the ability to alert on significant deviations in the data (and if you'd like, also on-going, running in the background as well). How it works video: &lt;A href="http://support.prelert.com/customer/portal/articles/1417340-quickmode"&gt;http://support.prelert.com/customer/portal/articles/1417340-quickmode&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;By the way, don't get caught up in trying to use standard deviation as your approach to express anomalousness. Standard deviation assumes that the data samples (in this case, "counts of events") conforms to a nice, symmetrical Gaussian Bell curve. In most cases, counts of things are better modeled by Poisson curves. Anomaly Detective automatically figures out the best statistical model for your data to maximize accuracy and minimize false alerting.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Oct 2014 19:37:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Standard-Deviation-of-Timechart/m-p/114120#M30133</guid>
      <dc:creator>prelert</dc:creator>
      <dc:date>2014-10-24T19:37:34Z</dc:date>
    </item>
  </channel>
</rss>

