Splunk Search

How to determine right value for Outlier Tolerance Threshold command in Smart Outlier Detection Assistant in MLTK app ?

dm1
Contributor

I am developing a use case to detect outliers on logons for a specific app using Smart Outlier Detection Assistant in MLTK app.

There is the Outlier Tolerance Threshold parameter in the Learn stage which I am unsure how to use.

The doc states "Adjust as needed based on the number of expected outliers."


how can someone know how many outliers they are expected ? To me, it doesn't makes sense as to how or why someone would already know this. Its what the usecase to indicate the number of outliers or maybe I am misinterpreting something.

 

Can someone please explain or direct me to some good documentation which properly explains this ?

 

Tags (1)
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...