Hm, I've used this very thing to detect spikes in incoming IP packets (using "daily packet count for protocol/port combo" as my averaged value) and simply using "average is less than 1/3 of next value" as a threshold for "something interesting just happened". I'm just wondering how good a technique that is.
no subject
Date: 2009-01-29 16:52 (UTC)