1 year ago

#387582

test-img

Daniel Price

Anomalydetection's Non existing by clause

The Search Command, Anomalydetection, does not have a by clause but I want to be able to group the data via a field, and run the Anomaly detection on each grouping separately.

Is there a way todo this in a contained report with out resorting to multiple reports/searches, one for each grouping.

splunk

0 Answers

Your Answer

Accepted video resources