Splunk Dev

How can I use anomalydetection on a subset of fields

dobbysocks
New Member

I am calculating several metrics (such as counts and rates) for the combination of time and usually at least one other dimension, with the intention of using the anomalydetection function to generate alerts on unexpected values. The issue I am running into is that the function sometimes generates an anomaly based on one of the grouping fields instead of on the metrics. When I try to use the fields-list parameter and only provide the metric columns it no longer filters down to the anomalies, instead it returns the entire dataset. It does this even if I explicitly set action=filter. I don't want to remove the grouping columns from the dataset completely because they are helpful for investigating the anomaly. The documentation doesn't include any examples of using the fields-list parameter. I was wondering if anyone has an example of successfully narrowing down to a subset of fields.

0 Karma
Get Updates on the Splunk Community!

Splunk AI Assistant for SPL | Key Use Cases to Unlock the Power of SPL

Splunk AI Assistant for SPL | Key Use Cases to Unlock the Power of SPL  The Splunk AI Assistant for SPL ...

Buttercup Games: Further Dashboarding Techniques (Part 5)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Customers Increasingly Choose Splunk for Observability

For the second year in a row, Splunk was recognized as a Leader in the 2024 Gartner® Magic Quadrant™ for ...