Splunk IT Service Intelligence

Splunk Anamoly detection for ODC Logs

New Member

Hello Splunk team and community,

I am working with the Splunk Machine Learning (ML) toolkit to detect anomalies in Oracle logs. Particularly, I have logs in Splunk that
contains both error and unerrored data, Is there any way where i need to detect anomalous in the logs says if there are suddenly some
50 errors received instead of normal by analyzing the history

If anyone has any ideas, tips, or guidance, I will be very grateful!


Tags (1)
0 Karma


Lots of people are going to recommend the out of the box anomaly detection in the MLTK to solve this.. While they are not wrong, this will lead to LOTS of Type 1 and Type 2 errors.

Check out my answer here on how to build out an anomaly detection framework in SPL


0 Karma
Get Updates on the Splunk Community!

User Groups | Upcoming Events!

If by chance you weren't already aware, the Splunk Community is host to numerous User Groups, organized ...

Splunk Lantern | Spotlight on Security: Adoption Motions, War Stories, and More

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Cloud | Empowering Splunk Administrators with Admin Config Service (ACS)

Greetings, Splunk Cloud Admins and Splunk enthusiasts! The Admin Configuration Service (ACS) team is excited ...