Splunk Search

When using outlier does it remove the entire log entry?

caffein
Path Finder

When using the outlier function will it remove the whole log entry from the set of values to process, or does it just remove individual values from their respective fields. For instance:

[rest of search]|outlier action=rm cnt

foo  bar  cnt 
1    10   5
2    15   6
1    10   100

                          avg(foo) avg(bar) avg(cnt)
All log #3 removed:       1.5      12.5     5.5
Just cnt outlier removed: 1.33     11.66    5.5
Tags (1)
0 Karma
1 Solution

sdaniels
Splunk Employee
Splunk Employee

When using the remove action (action=rm as you have above) it will remove the entire event containing the outlier value.

View solution in original post

sdaniels
Splunk Employee
Splunk Employee

When using the remove action (action=rm as you have above) it will remove the entire event containing the outlier value.

caffein
Path Finder

Perfect, thanks.

0 Karma
Get Updates on the Splunk Community!

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...