All Apps and Add-ons

Should we expect deteriorated performance while applying a learned model compared with fit command ?

bibinksebastian
Explorer

I am trying to forecast Tput_Gbps using smartforecasting . It works well when I fit the model . SPL: source="150daysABC - Copy.csv" host="forecast" index="150dayscopy" sourcetype="csv"
| reverse
| table _time Tput_Gbps Holiday_Flag | fit StateSpaceForecast "Tput_Gbps" as smartforecast output_metadata=true holdback=0 forecast_k=384 conf_interval=95 period=96 specialdays=Holiday_Flag into "_150_CD"
| tail 500 | table _time smartforecast Tput_Gbps
![alt text][1]

However, on the same data I tried to apply the model trained earlier. SPL: source="150daysABC - Copy.csv" host="forecast" index="150dayscopy" sourcetype="csv"
| reverse
| table _time Tput_Gbps Holiday_Flag | apply _150_CD

| tail 500 | table _time predicted(Tput_Gbps) Tput_Gbps

![alt text][2]

Towards the end of the prediction, I am seeing multiple predictions too. Looks very strange !! not sure how and why . Spent hours on troubleshooting this.

Please help to check if it is a bug or something that I am doing which is not right. @grana_splunk .This is in continuation to my earlier question. Thanks in advance for the help

0 Karma

grana_splunk
Splunk Employee
Splunk Employee

Is there any possibility, I can see your sample data? Without looking into it, I am not able to debug this issue further.

0 Karma

bibinksebastian
Explorer

I tried without specialdays input and specifying all the parameter necessary for apply method.
source="150daysAB - Copy.csv" host="forecast" index="150dayscopy" sourcetype="csv"
| reverse
| table _time Tput_Gbps Holiday_Flag | apply _150_AB3 holdback=0 forecast_k=384 conf_interval=95 period=96

| tail 500 | table _time predicted(Tput_Gbps) Tput_Gbps. It still gives me the same bad output

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...