All Apps and Add-ons

Help with multiple series forecasting

winknotes
Path Finder

I've read a few posts here related to this topic but can't find a workable solution.  

I have 200+ devices that I want to forecast Write Response Time for each device out 30 days.  My initial query to gather the data from a metric index is in a lookup table.  So I've tried this based on another similar post but I don't get any data for the predict command:

 

| inputlookup eg.csv
| dedupe device_name
| map maxsearches=5 search=" | inputlookup eg.csv | search device=$device_name$ | timechart span=1d avg(WriteRT) as avgWriteRT | predict avgWriteRT future_timespan=30 | eval device=$device_name$"
| table _time, WriteRT, "prediction(WriteRT)", device

 

I suspect it has something to do with 'search device=$device_name$' but unsure what that might be.  Running the inputlookup up to the predict command does return results minus the device_name.  

Labels (1)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...