Splunk Search

When using outlier does it remove the entire log entry?

caffein
Path Finder

When using the outlier function will it remove the whole log entry from the set of values to process, or does it just remove individual values from their respective fields. For instance:

[rest of search]|outlier action=rm cnt

foo  bar  cnt 
1    10   5
2    15   6
1    10   100

                          avg(foo) avg(bar) avg(cnt)
All log #3 removed:       1.5      12.5     5.5
Just cnt outlier removed: 1.33     11.66    5.5
Tags (1)
0 Karma
1 Solution

sdaniels
Splunk Employee
Splunk Employee

When using the remove action (action=rm as you have above) it will remove the entire event containing the outlier value.

View solution in original post

sdaniels
Splunk Employee
Splunk Employee

When using the remove action (action=rm as you have above) it will remove the entire event containing the outlier value.

caffein
Path Finder

Perfect, thanks.

0 Karma
Get Updates on the Splunk Community!

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...

Adoption of Infrastructure Monitoring at Splunk

  Splunk's Growth Engineering team showcases one of their first Splunk product adoption-Splunk Infrastructure ...