All Apps and Add-ons

Problem with MLTK to run a model

celianouguier
Explorer

Hi everyone,

I'm annoyed because I use the MLTK machine learning module to predict the score of one of my applications (using ITSI data).

For that I execute a request , I make a simple standardcalculation with a number of variables, then I run the model on my variables with standardcalculation and some other qualitative variables.

The model runs well and is saved.

When I then want to apply this model with the commands:

| apply Healthscore_Application_DB_StandardScaler_0 
| apply Healthscore_Application_DB

I have the following error

Error in 'apply' command: No valid events; check for null or non-numeric values in numeric fields

I don't understand why because I have this error also when I use exactly the same query as for learning. So there are necessarily valid events.

If anyone can help me, I'll be grateful.

0 Karma

astein_splunk
Splunk Employee
Splunk Employee

That error comes from Fit and Apply's data cleaning under the covers, check out https://docs.splunk.com/Documentation/MLApp/4.2.0/User/Understandfitandapply

when you do a |summary for the models can you see a completed model ?
When you build the models, are the permissions correctly set to use those models in another app (I think you are using ITSI for example) . https://docs.splunk.com/Documentation/MLApp/4.2.0/User/Models

Have you checked out the MLTK FAQ page for more guidance?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...