Hello, Last week I started with TrackMe App and so far I'm really impressed with all prebuild functionality. In the last days I was going through configurations step by step and applied them on data. Today I found some alerts due to outliers in sourcetypes, my problem is that in some cases I don't understand, why the eventcount in the outlierdetection got that high, because searching for index data in that time range is telling me everything is normal and the count is not that high as "detected". Below is the detected outlier with a count of 22: But indexed data is still at an eventcount of 1: Where is the count of 22 coming from? How to investigate on this, is there something that I maybe configured the wrong way? Many thanks and happy splunking, Sara
... View more