Splunk Enterprise

Splunk Machine Learning Toolkit: Density Function

Nick102
New Member

Hi, I'm trying to use the density function to detect anomalous logins compared to normal user usage.
I use the fit command like this

Nick102_0-1764605724215.png

and the apply command like this

Nick102_1-1764605752894.png

The result is the following

Nick102_2-1764605917765.png

I can't figure out why the log_likelihood anomaly_score columns aren't populated.

thank you for your help

Labels (1)
0 Karma

tscroggins
Champion

Hi @Nick102,

The DensityFunction algorithm has output fields IsOutlier(field), which can be renamed as part of the apply command, and BoundaryRanges.

Are you working from a specific example or reading documentation where a log_likelihood field is referenced?

0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...