Knowledge Management
Highlighted

What is the meaning of "probable_cause = eventtype" when using anomalydetection command?

New Member

When using the anomalydetection command the probable cause being returned is eventtype? What does this mean? I believe the event type for these events are all the same, yet this is being identified as the reason for the anomaly.

Ed

0 Karma
Highlighted

Re: What is the meaning of "probable_cause = eventtype" when using anomalydetection command?

Communicator

when I run anomalydetection probable_cause for me is the name of the field that is the outlier.

I'm trying to understand probablecausefreq, maxfreq, and logEvent_prob. The first 2 are [0,1] but the last one is [-21,11] and I can't find detailed documentation on the topic. I've only found \detectinganomalies and the MLTKcheatsheet.

My query is:
|inputcsv test.csv | anomalydetection "STDA" "STDB" action=annotate

Thank you!

0 Karma