How to Compute the mean activity volume per user in each hour yesterday, and find the ones more than n standard deviations above the mean?
Note: Considering user as a field
Any ideas about writing a search which satisfies the above condition?
try something like this,,
base search | timechart span=1h mean(user) as mean, stdev(user) AS std | where std>10 AND mean>10
By mean activity, I am assuming you mean the average.
| stats avg(count) by date_hour, user
For standard deviation you can try something like below. Replace "n" with your amount.
| eventstats stdev(count) as deviation | eval outlier=deviation*"n" | where count > outlier
try something like this,,
base search | timechart span=1h mean(user) as mean, stdev(user) AS std | where std>10 AND mean>10