Splunk Search

Use Dynamic Float Value with DBSCAN

Deniz_Oe
Explorer

Dear all! 

I am trying to use a dynamic value for my epsilon in the MLTK in Splunk:

 

map search="search index = cisco_prod 
| timechart span=1h count as logins_hour 
| timewrap w series=short| fields - logins_hour_s6|table logins_hour_s*|transpose 0| fit DBSCAN  \"row *\"  eps=$eps$"

 

 This doesn't return anything if eps is a float, only when I first round the dynamic variable.

However if I run the same search with a static float value for eps instead of my variable, it returns the clustering I am looking for.

Has anyone an idea what's wrong with my dynamic search? 

Thanks! 

0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...