All Apps and Add-ons

When to establish boundaries for MLTK based alerts?

SMM10
Explorer

I was working in the MLTK, very new to it and exploring. I was working to establish a few searches where I will fit a algorithm and then apply it to identify if any values out of a set boundary and then alert on that. I have two question from this.

 

Is this a valid use case or not so much?

I have a predicted value after my fit but, its too close to my actual values so I was thinking of doing something like(+ or - depending on need):

eval bound = (predictedavg - (stdev * 3))

 Would it be more beneficial to calculate this in the fit search or when applying the model?

Labels (2)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...