Install and set up the Splunk Machine Learning Toolkit

The Splunk Machine Learning Toolkit (MLTK) enables users to create, validate, manage, and operationalize machine-learning models through a guided user interface. Many of the searches provided in Splunk Security Content use MLTK to create models and enhance performance.

The current version of the Splunk Machine Learning Toolkit is 4.2.0 and requires Splunk Enterprise 6.6 or later or Splunk Cloud and Python for Scientific Computing add-on version 1.3 or 1.4.

To get started, download MLTK from Splunkbase and then visit this page for installation instructions.