All Apps and Add-ons

Machine learning toolkit: Null in isNormal field (OneClassSVM)

123martin
New Member

When I use "fit OneClassSVM * kernel="rbf" nu=0.5 coef0=0.5", I find that the isNormal field of some of the items display nothing. How can I deal with it?

0 Karma

aljohnson_splun
Splunk Employee
Splunk Employee

Hi @niketnilay,

The fit command is likely dealing with missing values during the fitting process where columns with missing values do not get predictions. Can you try doing

| table *
| fit OneClassSVM*

and confirm that the isNormal field is only empty for rows with missing values?

If that is the case, one way to get around it is by specifying which fields you want:

index=foo fieldone=* fieldtwo=* ... 

or you can consider using the fillnull command:

| fillnull

which will fill in zeros for missing values.

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...