Archive
Highlighted

When using outlier does it remove the entire log entry?

Path Finder

When using the outlier function will it remove the whole log entry from the set of values to process, or does it just remove individual values from their respective fields. For instance:

[rest of search]|outlier action=rm cnt

foo  bar  cnt 
1    10   5
2    15   6
1    10   100

                          avg(foo) avg(bar) avg(cnt)
All log #3 removed:       1.5      12.5     5.5
Just cnt outlier removed: 1.33     11.66    5.5
Tags (1)
0 Karma
Highlighted

Re: When using outlier does it remove the entire log entry?

Splunk Employee
Splunk Employee

When using the remove action (action=rm as you have above) it will remove the entire event containing the outlier value.

View solution in original post

Highlighted

Re: When using outlier does it remove the entire log entry?

Path Finder

Perfect, thanks.

0 Karma