All Apps and Add-ons

Splunk ML toolkit export Predictive models and Realtime scoring

thomas13t
Engager

Hello, I have a couple of questions regarding Splunk ML toolkit:

  1. Can I export Predictive models / algorithms from Splunk? If so what are the available exports: can it be code in python? can it be in R?

  2. The algorithms will need to run on (near)realtime data flows, can Splunk handle real time Predictive scoring? A scoring engine, something like SAS ESP (event stream processing), that can deployed separately form the Splunk instance?

Thx
Thomas

1 Solution

skoelpin
SplunkTrust
SplunkTrust

Hello,

1) Splunk uses the Python Scientific Compute add-on for its algorithms, so no, you cant export it, but you can use the Python based scientific compute kit

https://docs.splunk.com/Documentation/MLApp/3.1.0/User/Installandconfigure

2) It depends on a lot of things. How you set up your models, your hardware, your sample size, how many independent variables you have etc.. It's possible, but it depends

View solution in original post

0 Karma

skoelpin
SplunkTrust
SplunkTrust

Hello,

1) Splunk uses the Python Scientific Compute add-on for its algorithms, so no, you cant export it, but you can use the Python based scientific compute kit

https://docs.splunk.com/Documentation/MLApp/3.1.0/User/Installandconfigure

2) It depends on a lot of things. How you set up your models, your hardware, your sample size, how many independent variables you have etc.. It's possible, but it depends

0 Karma

thomas13t
Engager

Ok Thank you,

So if I understood correctly it could be theoretical possible to decouple the analytic part (creation, test, and validation of predictive models) from a "scoring" engine where the models are deployed, the needed flow (and eventual extra KPis are calculated) are present?

Or with your 2 answer you are implying that the splunk instance will be called via API everytime a resource needs a scoring and reply with the correct score?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Splunk Developer Day announcements: AI agents, MCP tools, Forecasting, and Custom ...

Splunk Developer Day was packed with product and platform updates for developers building in the AI ...