Alerting

Splunk Anomaly Detection for Logs

maheswar6523
New Member

Team,

Are there any working sample to create a POC on Splunk Anomaly Detection using Logs messages.
In our senario we need to notify admin if any login failure /Error received we need to notify an alert.

Thanks
Uma

Tags (1)
0 Karma

niketn
Legend

Two of the Starting points would be

1) Machine Learning Toolkit App
2) Splunk Security Essentials App

Some of the good blocks to read:
1) Anomaly Detection with Splunk IT Service Intelligence and Machine Learning Toolkit v3.2 series
2) Hunting With Splunk Series
3) Advanced Statistics Splunk Documentation

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...