All Apps and Add-ons

Can you use predict with split by function?

the_wolverine
Champion

Is there a way to split by using predict.

I can predict on a single factor, e.g.

| timechart span=1h max(values) as values | predict values

How about:

| timechart span=1h max(values) as values by user?

skoelpin
SplunkTrust
SplunkTrust

What is your exact use case here? What are you trying to predict?

It's possible your climbing the wrong ladder here

0 Karma

mraudaschl
Loves-to-Learn

I have the same problem/requirement.
What I want to do is to have predictions for counts of events in the timechart that is split by country, using trellis chart. Is there a way? The normal BY clause doesn't output anything when adding PREDICT

0 Karma

adonio
Ultra Champion

saw a nice answer by @kmorris_splunk on this subject but couldnt find it now. maybe he will see my ping and will be able to locate it better

0 Karma

kmorris_splunk
Splunk Employee
Splunk Employee

Here it is: https://answers.splunk.com/answers/661506/predict-with-wildcard.html#answer-661742

This was a slightly different scenario, but it may be helpful.

0 Karma

the_wolverine
Champion

Thanks but the example did not support an actual by-clause

index=_internal sourcetype=splunkd*
| stats count by sourcetype
| map search="search index=_internal sourcetype=$sourcetype$ | timechart count as $sourcetype$ | predict $sourcetype$"
| stats values(*) as * by _time

I need predict to support "timechart count as $sourcetype$ by host" for example.

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...