Splunk Dev

how to customize the mltk model predefined in escu rules

lily
Engager

Hi, I am lily.

I want to know how to customize the MLTK model using in ESCU rules.

If it doesn't, it is possible to check the contents of models inside the MLTK?  

<example>
I want to know how 'count_by_http_method_by_src_1d' was made

lily_0-1714095849802.png

 

Tags (1)

Ismail_BSA
Path Finder

I am also interested by this question 

0 Karma

hl
Path Finder

Same , I see that there are missing models also. When I event went to the ONNX github I still can't find the models that the splunk query is using for the mltk. 

 

```

| tstats `summariesonly` dc(All_Traffic.src) as src_count,count as total_count from datamodel=Network_Traffic.All_Traffic | apply app:network_traffic_src_count_30m [|`get_qualitative_upper_threshold(extreme)`] | apply app:network_traffic_count_30m [|`get_qualitative_upper_threshold(extreme)`] | search "IsOutlier(src_count)"=1 OR "IsOutlier(total_count)"=1

```

Where is this located  ? 

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...