All Apps and Add-ons

When to establish boundaries for MLTK based alerts?

SMM10
Explorer

I was working in the MLTK, very new to it and exploring. I was working to establish a few searches where I will fit a algorithm and then apply it to identify if any values out of a set boundary and then alert on that. I have two question from this.

 

Is this a valid use case or not so much?

I have a predicted value after my fit but, its too close to my actual values so I was thinking of doing something like(+ or - depending on need):

eval bound = (predictedavg - (stdev * 3))

 Would it be more beneficial to calculate this in the fit search or when applying the model?

Labels (2)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

🍂 Fall into November with a fresh lineup of Community Office Hours, Tech Talks, and Webinars we’ve ...

Transform your security operations with Splunk Enterprise Security

Hi Splunk Community, Splunk Platform has set a great foundation for your security operations. With the ...

Splunk Admins and App Developers | Earn a $35 gift card!

Splunk, in collaboration with ESG (Enterprise Strategy Group) by TechTarget, is excited to announce a ...