All Apps and Add-ons

Linux Auditd app - Is the SPL for the Anomalous Event Volume panel broken?

chris_barrett
SplunkTrust
SplunkTrust

We've just installed version 3..0.0 of the App on a v7.1.1 system and I suspect that the SPL for the Anomalous Event Volume search is broken.

The rename portion is: ... | rename lower95(prediction(count)) as lower, upper95(prediction(count)) as upper | ... but the predict command is being used to predict count but naming it as 'prediction', which is causing the renames to fail. I believe that the fix is to remove the "as prediction" from the predict command.

Is anyone able to confirm if this is the case?

Tags (1)
1 Solution

doksu
Contributor

Thanks very much for letting me know. It’s now been rectified in v3.0.1 and published on Splunkbase.

View solution in original post

doksu
Contributor

Thanks very much for letting me know. It’s now been rectified in v3.0.1 and published on Splunkbase.

doksu
Contributor

Yes, I think you’re right. Please standby for an update. Should be available by Monday.

Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...