For the Splunk App for Anomaly Detection documentation, see https://docs.splunk.com/Documentation/AnomalyApp
Datasets
This application may contain certain sample files and datasets, which are provided for your convenience only. Such files and datasets contain information and data compiled by third parties, and Splunk makes no representation or warranty that the data contained in such files and datasets are true, accurate, complete, or sanitized.
This release of the Splunk App for Anomaly Detection comes with several enhancements, in both the app workflow and the machine learning algorithm that powers it.
The app has a new remediation workflow. We can detect whether the input time series has missing data or is unevenly spaced. If the data is unevenly spaced, we provide an aggregation capability to create an evenly-spaced time series. If there is missing data, we fill it in via linear interpolation.
In this version, we expand our alert actions from email only to include “Log event”, “Output results to lookup”, “Output results to telemetry endpoint”, “Send to Splunk Mobile”, “Webhook”, and “Add to Triggered Alerts”.
We have also enhanced our Job Dashboard. The dropdown for each job shows its properties, including the sensitivity, the saved search schedule, and the alert actions selected for both anomaly and missing data alerting.
Behind the scenes, we have also significantly improved our anomaly detection algorithm.
This is the first Splunk-supported GA version of the Splunk App for Anomaly Detection (AnomalyApp)
This version lets you find anomalies in your time series dataset in just a couple of clicks
This version includes sensitivity adjustment so that you can set the sensitivity of the anomaly detection to low, medium or high
In this version, the app runs a health diagnostic on the time series to make sure the data is suitable for anomaly detection
This version includes a whole host of features to operationalize the anomaly detection job once it is created - user can schedule the job to run at a regular cadence and set alerts to trigger on certain conditions
Every anomaly has a confidence score associated with it to signify the severity of the anomaly
The visualizations for the anomalies has been improved; the app shows both point and interval anomalies
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.