- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Can you help me with an extreme search problem I'm having on Splunk Enterprise Security?

chrischen2018
New Member
09-30-2018
01:49 PM
Dynamic threshold for the Concept: min, low, high, extreme. Are there numerical values in each of the semantic terms? if yes, how do i modify them? If the modifications are to create our own custom semantic terms, then how do i create my own custom semantic terms?
I understand that the Domain: requires a minimum, a maximum, and a total count of events. once i have the output for total count events (runs by a scheduled search) which will be a numerical value. How does this total count numerical value correlate to the concept OR to the context OR the extreme search itself?
