All Apps and Add-ons

What are the hardware requirements for using the Machine Learning Toolkit?

packet_hunter
Contributor

Hi,

Can anyone list the hardware requirements and dependencies associated with using the Machine Learning Toolkit?

I think it's awesome and want to start using it.

For example, do you need a dedicated search head? What is the ideal configuration? Do the models create volumes and take up space? I have a complex Core and Splunk Enterprise Security deployment and I want to know how installing and using the MLTK will affect storage, licensing(indexing/day), performance, etc.

Can anyone point me to the documentation related to these concerns?

Thank you

0 Karma
1 Solution

inventsekar
SplunkTrust
SplunkTrust
0 Karma

packet_hunter
Contributor

Thank you, this should help a lot.

0 Karma

grana_splunk
Splunk Employee
Splunk Employee

May be you can check our Machine learning Performance App i.e. https://splunkbase.splunk.com/app/3289/

Using the dashboard in this app, you can browse the results of performance testing of ML-SPL. For each algorithm implemented in ML-SPL, we measure running time, CPU utilization, memory utilization, and disk activity when fitting models on up to 1,000,000 search results, and applying models on up to 10,000,000 search results, each with up to 50 fields.

0 Karma

packet_hunter
Contributor

Thank you for the suggestion. Can you share any anonymous information with me in regards to space requirements you have seen when fitting an algorithm to your data and applying a model to new data? Did you have to significantly increase storage capacity? I am relatively new to the admin side of splunk, and was looking to predict if we need more resources, and did not want to impact what's currently running.

0 Karma

grana_splunk
Splunk Employee
Splunk Employee

Model size varies with different algorithm but you can control the size of model by configuring it in mlspl.conf

Check this out : http://docs.splunk.com/Documentation/MLApp/2.0.1/User/Customsearchcommands#Configure_the_fit_and_app...

inventsekar
SplunkTrust
SplunkTrust

maybe, please check this -
Machine Learning Toolkit User Guide -
http://docs.splunk.com/Documentation/MLApp/2.0.0/User/Installandconfigure

0 Karma

packet_hunter
Contributor

Thank you for the link.
I have looked thru this again and I don't see anything addressing my concerns, maybe there is no issue with the MLTK or the /models sub folder etc...

0 Karma
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...