1 year ago
#387582
Daniel Price
Anomalydetection's Non existing by clause
The Search Command, Anomalydetection, does not have a by clause but I want to be able to group the data via a field, and run the Anomaly detection on each grouping separately.
Is there a way todo this in a contained report with out resorting to multiple reports/searches, one for each grouping.
splunk
0 Answers
Your Answer