Splunk Dev

How can I use anomalydetection on a subset of fields

dobbysocks
New Member

I am calculating several metrics (such as counts and rates) for the combination of time and usually at least one other dimension, with the intention of using the anomalydetection function to generate alerts on unexpected values. The issue I am running into is that the function sometimes generates an anomaly based on one of the grouping fields instead of on the metrics. When I try to use the fields-list parameter and only provide the metric columns it no longer filters down to the anomalies, instead it returns the entire dataset. It does this even if I explicitly set action=filter. I don't want to remove the grouping columns from the dataset completely because they are helpful for investigating the anomaly. The documentation doesn't include any examples of using the fields-list parameter. I was wondering if anyone has an example of successfully narrowing down to a subset of fields.

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...