<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Detecting anomaly in session eventcount in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Detecting-anomaly-in-session-eventcount/m-p/178839#M51450</link>
    <description>&lt;P&gt;Check out Splunk's "cluster" command (I assume you have already tried the "stdev" function of the "stats" command).&lt;/P&gt;</description>
    <pubDate>Fri, 01 May 2015 21:10:27 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2015-05-01T21:10:27Z</dc:date>
    <item>
      <title>Detecting anomaly in session eventcount</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Detecting-anomaly-in-session-eventcount/m-p/178838#M51449</link>
      <description>&lt;P&gt;We have data set which aggregated sessions with it's &lt;CODE&gt;eventcount&lt;/CODE&gt; for each event.&lt;BR /&gt;
We are looking at setting up an alert for sessions where eventcount exceeded "normalcy".&lt;/P&gt;

&lt;P&gt;For Bell-curved data we'd setup an alert for 2x or 3x &lt;STRONG&gt;STDEV&lt;/STRONG&gt;. But in our case eventcount is not really Bell-curved - as it starts right away very high at low &lt;CODE&gt;eventcount&lt;/CODE&gt; and then gradually gets lower in this manner&lt;BR /&gt;
x&lt;BR /&gt;
x&lt;BR /&gt;
xx&lt;BR /&gt;
xxxx&lt;BR /&gt;&lt;BR /&gt;
xxxxxxxxxxxxxxx&lt;/P&gt;

&lt;P&gt;Does Splunk has built-in ways to handle deviations for other types of non-Bell curved data sets?&lt;/P&gt;</description>
      <pubDate>Fri, 01 May 2015 20:16:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Detecting-anomaly-in-session-eventcount/m-p/178838#M51449</guid>
      <dc:creator>gesman</dc:creator>
      <dc:date>2015-05-01T20:16:38Z</dc:date>
    </item>
    <item>
      <title>Re: Detecting anomaly in session eventcount</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Detecting-anomaly-in-session-eventcount/m-p/178839#M51450</link>
      <description>&lt;P&gt;Check out Splunk's "cluster" command (I assume you have already tried the "stdev" function of the "stats" command).&lt;/P&gt;</description>
      <pubDate>Fri, 01 May 2015 21:10:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Detecting-anomaly-in-session-eventcount/m-p/178839#M51450</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-05-01T21:10:27Z</dc:date>
    </item>
    <item>
      <title>Re: Detecting anomaly in session eventcount</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Detecting-anomaly-in-session-eventcount/m-p/178840#M51451</link>
      <description>&lt;P&gt;You're very astute to recognize that using a "bell curve" Gaussian model (average and std. deviation) is not the most appropriate method to approach this. You could try the Prelert app (&lt;A href="https://splunkbase.splunk.com/app/1306/"&gt;https://splunkbase.splunk.com/app/1306/&lt;/A&gt;) to detect anomalies instead - it uses machine learning to automatically pick an appropriate probability distribution that best models your data, thus giving more accuracy to outlier detection.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Oct 2015 17:09:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Detecting-anomaly-in-session-eventcount/m-p/178840#M51451</guid>
      <dc:creator>richcollier</dc:creator>
      <dc:date>2015-10-23T17:09:34Z</dc:date>
    </item>
  </channel>
</rss>

