All Apps and Add-ons

When to establish boundaries for MLTK based alerts?

SMM10
Explorer

I was working in the MLTK, very new to it and exploring. I was working to establish a few searches where I will fit a algorithm and then apply it to identify if any values out of a set boundary and then alert on that. I have two question from this.

 

Is this a valid use case or not so much?

I have a predicted value after my fit but, its too close to my actual values so I was thinking of doing something like(+ or - depending on need):

eval bound = (predictedavg - (stdev * 3))

 Would it be more beneficial to calculate this in the fit search or when applying the model?

Labels (2)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...