All Apps and Add-ons

Unable to select Scoring Field in Behavioral Profiling - Anomaly Scoring Rule

varsha2233
New Member

Hello Splunk Community,

I’m working in the Behavioral Profiling app to create an Anomaly Scoring Rule.
In the Define Indicator Source step, I have successfully selected my Behavioral Indicator (e.g., "Amount Transaction"), but the Scoring Field dropdown is disabled / showing a red mark, and I’m unable to select any value.

Details:

Behavioral Indicator: Amount Transaction

Data is visible when I run the same SPL in Search & Reporting.

Time Range: Last Day (also tried other ranges)

Using the default fields from my dataset (contains account, amount, _time).

The Scoring Field dropdown does not show any options.


What I have tried:

Verified the field exists in my data.

Changed the Time Range to ensure data is available.

Recreated the Behavioral Indicator.


Question:
What specific requirements or field types does the Scoring Field expect?
Do I need to modify the Behavioral Indicator definition or SPL so that this dropdown is populated?

Any guidance or examples would be greatly appreciated.

Thanks in advance!

 

The Data that I have provided for profiling is as follows :

imestamp,account,amount
2025-08-11 11:25:56,ACC1001,2500
2025-08-11 11:25:56,ACC1001,3000
2025-08-11 11:25:56,ACC1001,5000
2025-08-11 11:25:56,ACC1002,1500
2025-08-11 11:25:56,ACC1002,2000
2025-08-11 11:25:56,ACC1003,8000
2025-08-11 11:25:56,ACC1003,4000
2025-08-11 11:25:56,ACC1004,12000
2025-08-11 11:25:56,ACC1005,600
2025-08-11 11:25:56,ACC1005,750
2025-08-11 11:25:56,ACC1006,5000
2025-08-11 11:25:56,ACC1006,7000

 

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...