When using the anomalydetection command the probable cause being returned is eventtype? What does this mean? I believe the event type for these events are all the same, yet this is being identified as the reason for the anomaly.
when I run anomalydetection probable_cause for me is the name of the field that is the outlier.
I'm trying to understand probablecausefreq, maxfreq, and logEvent_prob. The first 2 are [0,1] but the last one is [-21,11] and I can't find detailed documentation on the topic. I've only found \detectinganomalies and the MLTKcheatsheet.
My query is:
|inputcsv test.csv | anomalydetection "STDA" "STDB" action=annotate