- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hysteresis
Engager
10-08-2024
09:16 AM
I'm trying to implement the Splunk Machine Learning Toolkit Query, found here: https://github.com/splunk/security_content/blob/develop/detections/cloud/abnormally_high_number_of_c...
Actually just the first part:
| tstats count as all_changes from datamodel=Change_test where All_Changes.object_category=* All_Changes.status=* by All_Changes.object_category All_Changes.status All_Changes.user
But I'm getting this error
How do I fix this?
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
sainag_splunk

Splunk Employee
10-08-2024
01:28 PM
can you try adding this below line to the end of your search? and give it a try?
| noop search_optimization.predicate_push=f
https://docs.splunk.com/Documentation/SplunkCloud/latest/SearchReference/Noop#Managing_specific_sear...
Hope this Helps. Karma would be appreciated.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
sainag_splunk

Splunk Employee
10-08-2024
01:28 PM
can you try adding this below line to the end of your search? and give it a try?
| noop search_optimization.predicate_push=f
https://docs.splunk.com/Documentation/SplunkCloud/latest/SearchReference/Noop#Managing_specific_sear...
Hope this Helps. Karma would be appreciated.
