KB 102 (Splunk): PowerConnect Splunk App - Machine Learning Tool Kit (MLTK) Setup Guide
Version: 1 from 23.03.2021
Some of the dashboards available in the PowerConnect Splunkbase application utilize functionality from Splunk’s Machine Learning Tool Kit. To enable these panels, please following the instructions below.
Download “Splunk Machine Learning Toolkit” of version 4.5.0 or above from splunkbase – https://splunkbase.splunk.com/app/2890/
This app can be installed either through UI from “Manage Apps” or by extracting the compressed file into $SPLUNK_HOME$/etc/apps folder.
The following saved searches are used to improve the search performance for the MLTK panels by acceleration. By default this feature is disabled. Users need to manually enable the acceleration
“mltk_sap_security_essentials_anomaly_tcode” – For the “Anomaly Detection: T-Code Executions” panel present in SAP Security Essentials dashboard.
“mltk_sap_security_essentials_forecast_logins” – For the “Forecasting: User Logins” panel present in SAP Security Essentials dashboard.
“mltk_abap_dumps_forecast_dumps” – For the “Forecasting: ABAP dumps” panel present in ABAP Dumps dashboard.
The steps to change the acceleration are:
On Splunk’s menu bar, Click on Settings -> Searches, reports, and alerts.
Select SAP Powerconnect for Splunk (BNW-app-powerconnect) in App.
Click on “Edit” dropdown under “Actions” and click on “Edit Acceleration” for the savedsearch you want to enable acceleration for.
Under the Acceleration label, you will find “Accelerate this search” check box.
By making a check / uncheck “Accelerate Report” check box, the acceleration option of savedsearch will be enabled/disabled. Click on “Save” after making desired changes.
PowerConnect [NW,S4HANA,S4HANA Cloud]
[Affected version from]
[Affected version to]
[SAP product version]