Noisy alerts
Replace static thresholds with anomaly detection.
Anomaly detection, forecasting and analysis on your operational data, built into the tools you already work with.
Static thresholds do not know what time it is: they alert on every normal peak in activity and stay silent when unusual behaviour remains below the limit. And the historical data that could anticipate problems goes unused.
Five phases, always in the same order. Select each one to see what happens in it. In full projects they map onto the stages of our method.
We identify the use case, the data available, the risks and how success will be measured.
We design the solution: models, data, integrations, security controls and traceability.
We train the models on your historical data and integrate them into alerts and dashboards.
We compare false alarms and detected anomalies against the current thresholds over a trial period.
We tune the system based on real usage and monitor the system like any other production service.
The same metric over two days, watched two different ways. Move the fixed threshold and the model's sensitivity, and compare how many alerts each one fires and how many of the two real anomalies it catches.
Synthetic example series. The orange dots above are fixed-threshold alerts; the pink ones below are from the adaptive model.
In Splunk we solve this with adaptive thresholds in ITSI or with Machine Learning Toolkit models trained on your own history.
Replace static thresholds with anomaly detection.
Forecast when a resource will run out.
Detect behaviour that is out of the ordinary.
Not to get started. We use tools built into Splunk and document how to maintain the models.
With Machine Learning Toolkit and ITSI adaptive thresholds, the models run inside your Splunk environment.
It depends on the seasonality of the metric; usually several weeks to capture the weekly cycle.
Tell us about your situation. If this service is not what you need, we will tell you; if it is, we will propose a concrete first step.
Request this service