When using the outlier function will it remove the whole log entry from the set of values to process, or does it just remove individual values from their respective fields. For instance:
[rest of search]|outlier action=rm cnt
foo bar cnt
1 10 5
2 15 6
1 10 100
avg(foo) avg(bar) avg(cnt)
All log #3 removed: 1.5 12.5 5.5
Just cnt outlier removed: 1.33 11.66 5.5
When using the remove action (action=rm as you have above) it will remove the entire event containing the outlier value.
When using the remove action (action=rm as you have above) it will remove the entire event containing the outlier value.
Perfect, thanks.