Splunk IT Service Intelligence

Splunk Anamoly detection for ODC Logs

maheswar6523
New Member

Hello Splunk team and community,

I am working with the Splunk Machine Learning (ML) toolkit to detect anomalies in Oracle logs. Particularly, I have logs in Splunk that
contains both error and unerrored data, Is there any way where i need to detect anomalous in the logs says if there are suddenly some
50 errors received instead of normal by analyzing the history

If anyone has any ideas, tips, or guidance, I will be very grateful!

Thanks
Uma

Tags (1)
0 Karma

skoelpin
SplunkTrust
SplunkTrust

Lots of people are going to recommend the out of the box anomaly detection in the MLTK to solve this.. While they are not wrong, this will lead to LOTS of Type 1 and Type 2 errors.

Check out my answer here on how to build out an anomaly detection framework in SPL

https://answers.splunk.com/answers/590464/how-you-detect-an-anomaly-from-a-time-frame-the-pr.html#an...

0 Karma
Get Updates on the Splunk Community!

Enter the Dashboard Challenge and Watch the .conf24 Global Broadcast!

The Splunk Community Dashboard Challenge is still happening, and it's not too late to enter for the week of ...

Join Us at the Builder Bar at .conf24 – Empowering Innovation and Collaboration

What is the Builder Bar? The Builder Bar is more than just a place; it's a hub of creativity, collaboration, ...

Combine Multiline Logs into a Single Event with SOCK - a Guide for Advanced Users

This article is the continuation of the “Combine multiline logs into a single event with SOCK - a step-by-step ...