Other Usage

Unable to perform Seasonal-Trend decomposition on timechart

POR160893
Builder

Hi,

I have a timechart of number of events over a 7 day period and I need to run a Seasonal-Trend decomposition on the results.

This is my current query:
[BASE QUERY]
| timechart span=1h count
| streamstats window=24 avg(count) as hourly_avg_count
| timechart span=1h stl hourly_avg_count as seasonal component=longterm

However, I am getting the error: Unknown search command 'stl'.

Can you please help?

Many thanks!



Labels (3)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

I think the stl command is part of the Deep Learning Toolkit - do you have that installed?

0 Karma

POR160893
Builder
Spoiler
I don't sadly, not permitted in my work
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

OK then you may need to go back to basics and define what it is you would like to get from your data in terms of what commands you do have available.

0 Karma
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...