Knowledge Management

using splunk machine learning toolkit

sabaKhadivi
Path Finder

to use splunk machine learning toolkit app , do I have to define our network related lookups and put them in showcases algorithms? and replace our custom lookups instead of predefinde mlkt lookups?

Tags (1)
0 Karma

skoelpin
SplunkTrust
SplunkTrust

So you're asking if you want to do the same use cases as the showcase examples, if you can just add your own lookups and do the same? If so, then yeah you could do that, but it would be better to do it with the indexed data rather than lookups.

Also, it sounds like you're trying to find a solution to a problem you don't know you have. You'll have more success if you define a problem then find a solution in the MLTK

0 Karma

sabaKhadivi
Path Finder

so how can I define my problem into the MLTK?

0 Karma

sabaKhadivi
Path Finder

I mean how can I create my own showcase?

0 Karma

skoelpin
SplunkTrust
SplunkTrust

You wouldn't create a showcase, you will create an experiment. Go to the Experiments tab and select which type of use case this will be (i.e. predict a numeric value or category) and name your experiment. Then create a search or lookup table and build a model just like you did in the showcase

0 Karma

skoelpin
SplunkTrust
SplunkTrust

@sabaKhadivi did this answer your question? If so, can you accept?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Mastering Threat Intelligence in ES 8.5, Splunk AI Assistant v2, and More from Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...