I would like to use k-means clustering on a field (k=2) and then discard the search results in the cluster with the smaller mean. kmeans appends the CLUSTERNUM but not the values it converged to. I don't want to do a stats calculation on my result set because I have other commands I need to run, and kmeans has already calculated it anyway. Is it possible to do this?
You can use eventstats
to do this:
| eventstats avg(field) as avg by CLUSTERNUM | eventstats min(avg) as min | where min=avg
should losslessly filter the results.
I'd also suggest filing an enhancement request for kmeans to keep the means, so you can do this more directly.
You can use eventstats
to do this:
| eventstats avg(field) as avg by CLUSTERNUM | eventstats min(avg) as min | where min=avg
should losslessly filter the results.
I'd also suggest filing an enhancement request for kmeans to keep the means, so you can do this more directly.
Works for me, thanks.
I logged an enhancement request to update kmeans.