@thambisettyThanks for the reply!
This mentions mostly for numeric fields, I am looking for Zscore or histogram for string(character) field.
For Anomaly detection, on string field, which method is better - Zscore or histogram? Please suggest!
z--score, you should apply standard deviation to see how the values are deviating. with out count of strings, I don't know how you calculate zscore, or histogram.
https://conf.splunk.com/files/2019/recordings/FN1390.mp4