Splunk Search

For Anomaly detection, on string field, which method is better - Zscore or histogram?

VS0909
Communicator

For Anomaly detection, on string field, which method is better - Zscore or histogram? Please suggest

Labels (5)
0 Karma

VS0909
Communicator

@thambisettyThanks for the reply!

This mentions mostly for numeric fields, I am looking for Zscore or histogram for string(character) field.

For Anomaly detection, on string field, which method is better - Zscore or histogram? Please suggest!

0 Karma

thambisetty
SplunkTrust
SplunkTrust

z--score, you should apply standard deviation to see how the values are deviating. with out count of strings, I don't know how you calculate zscore, or histogram. 

————————————
If this helps, give a like below.

thambisetty
SplunkTrust
SplunkTrust

https://conf.splunk.com/files/2019/recordings/FN1390.mp4

————————————
If this helps, give a like below.
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...