Splunk Search
Highlighted

How to calculate Anomalies for a particular field?

Builder

Considering a field "username". What could be the search to find the anomalies per hour for each username in a day?

0 Karma
Highlighted

Re: How to calculate Anomalies for a particular field?

SplunkTrust
SplunkTrust

Give this a try

your base search | bucket span=1h _time | stats count by _time user_name | eventstats stdev(count) as stdev by user_name | where count>Your_MultiplicationFactor*stdev

View solution in original post