Is there a way to do ML jobs for a high count of a specific field ?
like i want high count of event.code 4626
Is there a way to do ML jobs for a high count of a specific field ?
like i want high count of event.code 4626
If you're talking about a specific field "value" (ie: event.code : 4626), you can achieve this via a saved search. With ML you can use saved searches instead of directly off of an index.
This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
© 2020. All Rights Reserved - Elasticsearch
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.