Is there a way to do ML jobs for a high count of a specific field ?
like i want high count of event.code 4626
Is there a way to do ML jobs for a high count of a specific field ?
like i want high count of event.code 4626
If you're talking about a specific field "value" (ie: event.code : 4626), you can achieve this via a saved search. With ML you can use saved searches instead of directly off of an index.
© 2020. All Rights Reserved - Elasticsearch
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.