All Apps and Add-ons

Splunk ML toolkit export Predictive models and Realtime scoring

thomas13t
Engager

Hello, I have a couple of questions regarding Splunk ML toolkit:

  1. Can I export Predictive models / algorithms from Splunk? If so what are the available exports: can it be code in python? can it be in R?

  2. The algorithms will need to run on (near)realtime data flows, can Splunk handle real time Predictive scoring? A scoring engine, something like SAS ESP (event stream processing), that can deployed separately form the Splunk instance?

Thx
Thomas

1 Solution

skoelpin
SplunkTrust
SplunkTrust

Hello,

1) Splunk uses the Python Scientific Compute add-on for its algorithms, so no, you cant export it, but you can use the Python based scientific compute kit

https://docs.splunk.com/Documentation/MLApp/3.1.0/User/Installandconfigure

2) It depends on a lot of things. How you set up your models, your hardware, your sample size, how many independent variables you have etc.. It's possible, but it depends

View solution in original post

0 Karma

skoelpin
SplunkTrust
SplunkTrust

Hello,

1) Splunk uses the Python Scientific Compute add-on for its algorithms, so no, you cant export it, but you can use the Python based scientific compute kit

https://docs.splunk.com/Documentation/MLApp/3.1.0/User/Installandconfigure

2) It depends on a lot of things. How you set up your models, your hardware, your sample size, how many independent variables you have etc.. It's possible, but it depends

0 Karma

thomas13t
Engager

Ok Thank you,

So if I understood correctly it could be theoretical possible to decouple the analytic part (creation, test, and validation of predictive models) from a "scoring" engine where the models are deployed, the needed flow (and eventual extra KPis are calculated) are present?

Or with your 2 answer you are implying that the splunk instance will be called via API everytime a resource needs a scoring and reply with the correct score?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...