All Apps and Add-ons

Help with multiple series forecasting

winknotes
Path Finder

I've read a few posts here related to this topic but can't find a workable solution.  

I have 200+ devices that I want to forecast Write Response Time for each device out 30 days.  My initial query to gather the data from a metric index is in a lookup table.  So I've tried this based on another similar post but I don't get any data for the predict command:

 

| inputlookup eg.csv
| dedupe device_name
| map maxsearches=5 search=" | inputlookup eg.csv | search device=$device_name$ | timechart span=1d avg(WriteRT) as avgWriteRT | predict avgWriteRT future_timespan=30 | eval device=$device_name$"
| table _time, WriteRT, "prediction(WriteRT)", device

 

I suspect it has something to do with 'search device=$device_name$' but unsure what that might be.  Running the inputlookup up to the predict command does return results minus the device_name.  

Labels (1)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...