# Splunk App for Data Science and Deep Learning - Anomaly Detection with the PyOD library
## Example for ECOD: Unsupervised Outlier Detection Using Empirical Cumulative Distribution Functions

[PyOD is the most comprehensive and scalable Python toolkit for detecting outlying objects in multivariate data.](https://pyod.readthedocs.io/en/latest/index.html)

This notebook contains an example workflow how to work on custom containerized code that seamlessly interfaces with you Splunk platform by utilizing the Splunk App for Data Science and Deep Learning (DSDL). Find more examples and information in the app and on the [DSDL splunkbase page](https://splunkbase.splunk.com/app/4607/#/details).

Note: By default every time you save this notebook the stages main cells are exported into a python module which can then get invoked by Splunk's MLTK SPL commands like <code> | fit ... | apply ... | summary </code>. Please read the Model Development Guide in the DSDL documentation for more information about this workflow.

## Stage 0 - import libraries
At stage 0 we define all imports necessary to run our subsequent code depending on various libraries.

In [1]:
# this definition exposes all python module imports that should be available in all subsequent commands
import json
import numpy as np
import pandas as pd
from pyod.models.ecod import ECOD
#from pyod.models.iforest import IForest
# ...
# global constants
MODEL_DIRECTORY = "/srv/app/model/data/"

In [2]:
# THIS CELL IS NOT EXPORTED - free notebook cell for testing or development purposes
print("numpy version: " + np.__version__)
print("pandas version: " + pd.__version__)

numpy version: 1.26.4
pandas version: 2.2.3


## Stage 1 - get a data sample from Splunk
There are currently 2 ways to retrieve data from Splunk: Option 1 is to interactively pull data from Splunk into the DLTK Jupyter Lab environment. This is useful when the Splunk REST API is accessible from the Jupyter environment and a valid Splunk auth token is defined in the DLTK app. This option has advantages to quickly experiment with different Splunk SPL queries and further interactively work with the search results in Jupyter.

### Option 1 - pull data from Splunk

In [4]:
from dsdlsupport import SplunkSearch as SplunkSearch

In [5]:
search = SplunkSearch.SplunkSearch(search='| inputlookup hostperf.csv \n| eval _time=strptime(_time, "%Y-%m-%dT%H:%M:%S.%3Q%z") \n| timechart span=10m max(rtmax) as responsetime')

VBox(children=(HBox(children=(Textarea(value='| inputlookup hostperf.csv \n| eval _time=strptime(_time, "%Y-%m…

In [5]:
df = search.as_df()
df

### Option 2 - push data from Splunk
In Splunk run a search to pipe a dataset into your notebook environment. You utilize the `mode=stage` flag in the in the `| fit` command to do this. The search results are accessible then as csv file with the same model name that is defined in the `into app:<modelname>` part of the fit statement. Additionally, meta data is retrieved and accessible as json file. In the same way you can further work with the meta data object as it is exposed in the fit and apply function definitions below in stage 3 and 4.

| inputlookup hostperf.csv <br>
| eval _time=strptime(_time, "%Y-%m-%dT%H:%M:%S.%3Q%z") <br>
| timechart span=10m max(rtmax) as responsetime<br>
| fit MLTKContainer mode=stage algo=anomaly_detection_ecod responsetime into app:anomaly_detection_ecod_responsetime


After you run this search your data set sample is available as a csv inside the container to develop your model. The name is taken from the into keyword ("barebone_model" in the example above) or set to "default" if no into keyword is present. This step is intended to work with a subset of your data to create your custom model.

In [6]:
# this cell is not executed from MLTK and should only be used for staging data into the notebook environment
def stage(name):
    with open("data/"+name+".csv", 'r') as f:
        df = pd.read_csv(f)
    with open("data/"+name+".json", 'r') as f:
        param = json.load(f)
    return df, param

In [9]:
# THIS CELL IS NOT EXPORTED - free notebook cell for testing or development purposes
df, param = stage("anomaly_detection_ecod_responsetime")

In [10]:
df

Unnamed: 0,responsetime
0,1.275
1,5.933
2,5.599
3,2.839
4,3.702
...,...
1019,6.892
1020,4.894
1021,2.898
1022,7.564


In [9]:
param

{'options': {'params': {'mode': 'stage', 'algo': 'anomaly_detection_ecod'},
  'args': ['bytes'],
  'feature_variables': ['bytes'],
  'model_name': 'anomaly_detection_bytes',
  'algo_name': 'MLTKContainer',
  'mlspl_limits': {'disabled': False,
   'handle_new_cat': 'default',
   'max_distinct_cat_values': '10000',
   'max_distinct_cat_values_for_classifiers': '10000',
   'max_distinct_cat_values_for_scoring': '10000',
   'max_fit_time': '6000',
   'max_inputs': '10000000',
   'max_memory_usage_mb': '16000',
   'max_model_size_mb': '3000',
   'max_score_time': '6000',
   'use_sampling': '1'},
  'kfold_cv': None},
 'feature_variables': ['bytes']}

## Stage 2 - create and initialize a model

In [10]:
# initialize your model
# available inputs: data and parameters
# returns the model object which will be used as a reference to call fit, apply and summary subsequently
def init(df,param):
    model = ECOD(contamination=0.01)
    # parallization options for ECOD:
    # ECOD(n_jobs=2)    
    # most of other PyOD models would work similar, e.g. replace with Isolation Forest:
    # model = IForest()

    return model

In [11]:
# THIS CELL IS NOT EXPORTED - free notebook cell for testing or development purposes
model = init(df,param)
print(model)

ECOD(contamination=0.01, n_jobs=1)


## Stage 3 - fit the model

In [12]:
# train your model
# returns a fit info json object and may modify the model object
def fit(model,df,param):
    X = df[param['feature_variables'][0]]
    X_train = np.reshape(X.to_numpy(), (len(X), 1))

    # contamination = 0.01
    model.fit(X_train)
    
    info = {"message": "model trained"}
    return info

In [13]:
# THIS CELL IS NOT EXPORTED - free notebook cell for testing or development purposes
print(fit(model,df,param))

{'message': 'model trained'}


## Stage 4 - apply the model

In [14]:
# apply your model
# returns the calculated results
def apply(model,df,param):
    X = df[param['feature_variables'][0]]
    X_apply = np.reshape(X.to_numpy(), (len(X), 1))
    
    y_hat = model.predict(X_apply)  # outlier labels (0 or 1)
    y_scores = model.decision_function(X_apply)  # outlier scores

    result = pd.DataFrame(y_hat, columns=['outlier'])
    return result

In [15]:
# THIS CELL IS NOT EXPORTED - free notebook cell for testing or development purposes
print(apply(model,df,param))

       outlier
0            0
1            0
2            0
3            0
4            0
...        ...
37607        0
37608        0
37609        0
37610        0
37611        0

[37612 rows x 1 columns]


## Stage 5 - save the model

In [16]:
# save model to name in expected convention "<algo_name>_<model_name>"
def save(model,name):
    if model is not None:
        if isinstance(model,ECOD):
            from joblib import dump, load
            dump(model, MODEL_DIRECTORY + name + '.joblib')
    return model

## Stage 6 - load the model

In [17]:
# load model from name in expected convention "<algo_name>_<model_name>"
def load(name):
    model = {}
    from joblib import dump, load
    model = load(model, MODEL_DIRECTORY + name + '.joblib')
    return model

## Stage 7 - provide a summary of the model

In [18]:
# return a model summary
def summary(model=None):
    returns = {"version": {"numpy": np.__version__, "pandas": pd.__version__} }
    return returns

## End of Stages
All subsequent cells are not tagged and can be used for further freeform code

In [19]:
# future: further explore SUOD
# please install suod first for SUOD by `pip install suod`
#from pyod.models.suod import SUOD

# initialized a group of outlier detectors for acceleration
#detector_list = [ECOD(), LOF(n_neighbors=35), IForest(n_estimators=100)]

# decide the number of parallel process, and the combination method
# then clf can be used as any outlier detection model
#clf = SUOD(base_estimators=detector_list, n_jobs=2, combination='average', verbose=False)