Splunk Search

Searching in model created with TDIDF, StandardScaler and PCA

Madere
Observer

Hi All,

I followed Ian's blog (https://blog.arcusdata.io/splunk-mltk-to-predict-kb-articles) and it is a nice blog.

But what I am missing: how to search (makeresult) in the model with a description like "Unsupported Java version". When performing a search with this text on the model, I think/expect "KB0020147" (or another KB number that fits better according the model) to be returned as result.

I suspect the search string looks like:

| makeresults | eval description="Unsupported Java version" | apply <ModelName> as Predicted_KB

But I think this won't work because the description needs to be prepared first to fit on the model values (PC_1, PC_2 and PC_3) which are numeric.

Does anyone has an idea how the search/makeresult string would look like?

Thanks.

Regards,

Madere

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...