All Apps and Add-ons

Understanding "by" grouping and anomaly detection


I wanted to make sure I understand an mstats query that has a "by" clause at the end with regard to machine learning toolkit.

| mstats avg(metric) where index="myindex" by dimension_name

When I choose the dimension name and the metric for detecting categorical outliers are the results based on outliers per dimension or compared to all metrics regardless of the dimension? I think and hope it's the former but wanted to clarify.

Thank you in advance.

Get Updates on the Splunk Community!

tag as datamodel attribute

I'm confused a bit. I use CIM datamodels.The "tag" field is both a filter for choosing events applicable to a ...

Index with one sourcetype - search performance / best practices

Hello,I have created a few indexes, each containing data only from one source with one sourcetype.<BR />From a ...

Can you customize Additional Fields in Notable Events?

Is there a way to customize which additional fields to show for which Notable event /Co-relation search ...