Thanks, Here is a little more information.
Uploading the csv -
Whitelist
N/A
Blacklist
N/A
Source Type
Automatic
App Context
Splunk_ML_Toolkit
Host
SplunkLab1
The search doesn't seem to change the output, but it is below.
index=REMOVED source="/home/downloads/REMOVED*" | head 100
I select an event and below is what I see for every field and value.
INDISCARDS DERIVE
INERRORS DERIVE
INMULTICASTPKTS DERIVE
If I then select a field I see below.
Values Count %
DERIVE 25 100%
When I try to create a model in MLTK with the same search it then creates the error I provided earlier.
Hope that helps. Thanks,
... View more