All Apps and Add-ons

Linux Auditd app - Is the SPL for the Anomalous Event Volume panel broken?

chris_barrett
SplunkTrust
SplunkTrust

We've just installed version 3..0.0 of the App on a v7.1.1 system and I suspect that the SPL for the Anomalous Event Volume search is broken.

The rename portion is: ... | rename lower95(prediction(count)) as lower, upper95(prediction(count)) as upper | ... but the predict command is being used to predict count but naming it as 'prediction', which is causing the renames to fail. I believe that the fix is to remove the "as prediction" from the predict command.

Is anyone able to confirm if this is the case?

Tags (1)
1 Solution

doksu
Contributor

Thanks very much for letting me know. It’s now been rectified in v3.0.1 and published on Splunkbase.

View solution in original post

doksu
Contributor

Thanks very much for letting me know. It’s now been rectified in v3.0.1 and published on Splunkbase.

doksu
Contributor

Yes, I think you’re right. Please standby for an update. Should be available by Monday.

Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...