Considering a field "username". What could be the search to find the anomalies per hour for each username in a day?
Give this a try
your base search | bucket span=1h _time | stats count by _time user_name | eventstats stdev(count) as stdev by user_name | where count>Your_MultiplicationFactor*stdev
View solution in original post