We've just installed version 3..0.0 of the App on a v7.1.1 system and I suspect that the SPL for the Anomalous Event Volume search is broken.
The rename portion is: ... | rename lower95(prediction(count)) as lower, upper95(prediction(count)) as upper |
... but the predict command is being used to predict count but naming it as 'prediction', which is causing the renames to fail. I believe that the fix is to remove the "as prediction" from the predict command.
Is anyone able to confirm if this is the case?
Thanks very much for letting me know. It’s now been rectified in v3.0.1 and published on Splunkbase.
Thanks very much for letting me know. It’s now been rectified in v3.0.1 and published on Splunkbase.
Yes, I think you’re right. Please standby for an update. Should be available by Monday.