Thanks for the reply.
I am looking to trigger an alert in splunk if the frequency of an error (log_level=error) increases in server logs as compared to its threshold value. I have index for logs index=Serverlogs1.
Threshold value should be calculated dynamically based on past one week server logs.
Please help.
check below video, it uses machine learning to detect numerical outliers and also video describes how to use standard deviation ( with out machine learning) this may help you.
https://conf.splunk.com/files/2019/recordings/FN1390.mp4