All Apps and Add-ons

Understanding "by" grouping and anomaly detection

winknotes
Path Finder

I wanted to make sure I understand an mstats query that has a "by" clause at the end with regard to machine learning toolkit.

| mstats avg(metric) where index="myindex" by dimension_name

When I choose the dimension name and the metric for detecting categorical outliers are the results based on outliers per dimension or compared to all metrics regardless of the dimension? I think and hope it's the former but wanted to clarify.

Thank you in advance.

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...