Splunk Search

For Anomaly detection, on string field, which method is better - Zscore or histogram?

VS0909
Communicator

For Anomaly detection, on string field, which method is better - Zscore or histogram? Please suggest

Labels (5)
0 Karma

VS0909
Communicator

@thambisettyThanks for the reply!

This mentions mostly for numeric fields, I am looking for Zscore or histogram for string(character) field.

For Anomaly detection, on string field, which method is better - Zscore or histogram? Please suggest!

0 Karma

thambisetty
SplunkTrust
SplunkTrust

z--score, you should apply standard deviation to see how the values are deviating. with out count of strings, I don't know how you calculate zscore, or histogram. 

————————————
If this helps, give a like below.

thambisetty
SplunkTrust
SplunkTrust

https://conf.splunk.com/files/2019/recordings/FN1390.mp4

————————————
If this helps, give a like below.
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...