Splunk® Machine Learning Toolkit

User Guide

This documentation does not apply to the most recent version of Splunk® Machine Learning Toolkit. For documentation on the most recent version, go to the latest release.

Install the ML-SPL Performance App

Machine learning requires compute resources and disk space. Each algorithm has a different performance cost, which can be complicated by the number of input fields you select and the total number of events processed. Model files are lookups and do increase bundle replication costs.

For each algorithm implemented in ML-SPL, run time, CPU utilization, memory utilization, and disk activity are measured when fitting models on up to 1,000,000 search results, and applying models on up to 10,000,000 search results, each with up to 50 fields.

Through the Settings tab of the MLTK, on-prem users with Admin access can configure the settings of the fit and apply commands. Changes can be made across all algorithms, or for an individual algorithm. Splunk Cloud users need to create a support ticket to change these settings.

For more information, see Configure algorithm performance costs.

The ML-SPL Performance App for the Machine Learning Toolkit enables users to:

  • Ensure you know the impact of making changes to the default performance cost Settings.
  • Access performance results for guidance purposes.
  • Access performance results for bench-marking purposes.

To learn more about this add-on and to download, see Splunkbase for the ML-SPL Performance App for the Machine Learning Toolkit.

Splunk Cloud users need to open a support ticket in order to install this app.

Last modified on 26 November, 2019
Install the Machine Learning Toolkit   Install the GitHub for Machine Learning App

This documentation applies to the following versions of Splunk® Machine Learning Toolkit: 4.4.0, 4.4.1, 4.4.2, 4.5.0


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters