Splunk Search

Running a prediction and anomaly detection in parallel

zkn9ce6
New Member

I want to build a query that can do the following.

a. Monitor about 10-15 metrics from the different kinds of system/application logs
b. Identify anomalies in these metrics, and if any anomaly is identified in one of the metrics, then run them through a if else loop to check if similar kind of metrics also had an anomaly.
c. if similar metrics had an anomaly, then use the predict command to predict values for the next x mins and identify if they are breaching the SLA's
d. If they are breaching then send out an alert.

We have been able to come till point C. but we are unable to predict values for multiple metrics at same time in parallel and check if they are breaching the SLA.

Does it need an external code or can it be done via Splunk?

Please advise.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...