For the below search
My search | timechart span=1h limit=0 count by student
Is it possible to list out the anomalous for each student?
Thanks in advance!
here is the doc for anomalydetection
https://docs.splunk.com/Documentation/Splunk/6.5.0/SearchReference/Anomalydetection
this should return outliers
My search | timechart span=1h limit=0 count by student|anomalydetection method=iqr action=tf param=4 uselower=true mark=true
Have you tried...
My search | timechart span=1h limit=0 count by student | anomalies by student
here is the doc for anomalydetection
https://docs.splunk.com/Documentation/Splunk/6.5.0/SearchReference/Anomalydetection
this should return outliers
My search | timechart span=1h limit=0 count by student|anomalydetection method=iqr action=tf param=4 uselower=true mark=true