Skip to content
Discussion options

You must be logged in to vote

I think this sounds like a good fit for OpenSearch Dashboards' Anomaly Detection feature. I think I would start by creating a detector on network.bytes and then create a bucket probably on source.ip or maybe related.ip. See the opensearch dashboards and opensearch documentation for more info.

Note that, in my experience at least, since this model is self-training, determining the baseline takes at least a couple of weeks' worth of data before you start getting useful anomalies. But once it's been running for a while on your data set it becomes pretty accurate.

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@y0d4a
Comment options

Answer selected by y0d4a
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
dashboards Relating to Malcolm's OpenSearch Dashboards interface opensearch Relating to Malcolm's use of OpenSearch
2 participants