Other Usage

Unable to perform Seasonal-Trend decomposition on timechart

POR160893
Builder

Hi,

I have a timechart of number of events over a 7 day period and I need to run a Seasonal-Trend decomposition on the results.

This is my current query:
[BASE QUERY]
| timechart span=1h count
| streamstats window=24 avg(count) as hourly_avg_count
| timechart span=1h stl hourly_avg_count as seasonal component=longterm

However, I am getting the error: Unknown search command 'stl'.

Can you please help?

Many thanks!



Labels (2)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

I think the stl command is part of the Deep Learning Toolkit - do you have that installed?

0 Karma

POR160893
Builder
Spoiler
I don't sadly, not permitted in my work
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

OK then you may need to go back to basics and define what it is you would like to get from your data in terms of what commands you do have available.

0 Karma
Get Updates on the Splunk Community!

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...

Your Voice Matters! Help Us Shape the New Splunk Lantern Experience

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...