Splunk Search

How to determine right value for Outlier Tolerance Threshold command in Smart Outlier Detection Assistant in MLTK app ?

dm1
Contributor

I am developing a use case to detect outliers on logons for a specific app using Smart Outlier Detection Assistant in MLTK app.

There is the Outlier Tolerance Threshold parameter in the Learn stage which I am unsure how to use.

The doc states "Adjust as needed based on the number of expected outliers."


how can someone know how many outliers they are expected ? To me, it doesn't makes sense as to how or why someone would already know this. Its what the usecase to indicate the number of outliers or maybe I am misinterpreting something.

 

Can someone please explain or direct me to some good documentation which properly explains this ?

 

Tags (1)
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...