Splunk Dev

how to customize the mltk model predefined in escu rules

lily
Engager

Hi, I am lily.

I want to know how to customize the MLTK model using in ESCU rules.

If it doesn't, it is possible to check the contents of models inside the MLTK?  

<example>
I want to know how 'count_by_http_method_by_src_1d' was made

lily_0-1714095849802.png

 

Tags (1)

Ismail_BSA
Path Finder

I am also interested by this question 

0 Karma

hl
Path Finder

Same , I see that there are missing models also. When I event went to the ONNX github I still can't find the models that the splunk query is using for the mltk. 

 

```

| tstats `summariesonly` dc(All_Traffic.src) as src_count,count as total_count from datamodel=Network_Traffic.All_Traffic | apply app:network_traffic_src_count_30m [|`get_qualitative_upper_threshold(extreme)`] | apply app:network_traffic_count_30m [|`get_qualitative_upper_threshold(extreme)`] | search "IsOutlier(src_count)"=1 OR "IsOutlier(total_count)"=1

```

Where is this located  ? 

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...