Splunk Search

How to determine right value for Outlier Tolerance Threshold command in Smart Outlier Detection Assistant in MLTK app ?

dm1
Contributor

I am developing a use case to detect outliers on logons for a specific app using Smart Outlier Detection Assistant in MLTK app.

There is the Outlier Tolerance Threshold parameter in the Learn stage which I am unsure how to use.

The doc states "Adjust as needed based on the number of expected outliers."


how can someone know how many outliers they are expected ? To me, it doesn't makes sense as to how or why someone would already know this. Its what the usecase to indicate the number of outliers or maybe I am misinterpreting something.

 

Can someone please explain or direct me to some good documentation which properly explains this ?

 

Tags (1)
Get Updates on the Splunk Community!

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Community Feedback

We Want to Hear from You! Share Your Feedback on the Splunk Community   The Splunk Community is built for you ...

Manual Instrumentation with Splunk Observability Cloud: Implementing the ...

In our observability journey so far, we've built comprehensive instrumentation for our Worms in Space ...