Splunk Search

Running a prediction and anomaly detection in parallel

New Member

I want to build a query that can do the following.

a. Monitor about 10-15 metrics from the different kinds of system/application logs
b. Identify anomalies in these metrics, and if any anomaly is identified in one of the metrics, then run them through a if else loop to check if similar kind of metrics also had an anomaly.
c. if similar metrics had an anomaly, then use the predict command to predict values for the next x mins and identify if they are breaching the SLA's
d. If they are breaching then send out an alert.

We have been able to come till point C. but we are unable to predict values for multiple metrics at same time in parallel and check if they are breaching the SLA.

Does it need an external code or can it be done via Splunk?

Please advise.

0 Karma
.conf21 Now Fully Virtual!
Register for FREE Today!

We've made .conf21 totally virtual and totally FREE! Our completely online experience will run from 10/19 through 10/20 with some additional events, too!