Splunk Search

For Anomaly detection, on string field, which method is better - Zscore or histogram?

VS0909
Communicator

For Anomaly detection, on string field, which method is better - Zscore or histogram? Please suggest

Labels (5)
0 Karma

VS0909
Communicator

@thambisettyThanks for the reply!

This mentions mostly for numeric fields, I am looking for Zscore or histogram for string(character) field.

For Anomaly detection, on string field, which method is better - Zscore or histogram? Please suggest!

0 Karma

thambisetty
SplunkTrust
SplunkTrust

z--score, you should apply standard deviation to see how the values are deviating. with out count of strings, I don't know how you calculate zscore, or histogram. 

————————————
If this helps, give a like below.

thambisetty
SplunkTrust
SplunkTrust

https://conf.splunk.com/files/2019/recordings/FN1390.mp4

————————————
If this helps, give a like below.
Get Updates on the Splunk Community!

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...

Brains, Bytes, and Boston: Learn from the Best at .conf25

When you think of Boston, you might picture colonial charm, world-class universities, or even the crack of a ...