# Add a condition on ML

**URL:** <https://discuss.elastic.co/t/add-a-condition-on-ml/255358>\
**Category:** Kibana\
**Tags:** elastic-stack-machine-learning\
**Created:** [November 13, 2020, 3:00pm UTC](https://discuss.elastic.co/t/add-a-condition-on-ml/255358 "2020-11-13T15:00:14Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![AmS](https://avatars.discourse-cdn.com/v4/letter/a/a4c791/32.png) [@AmS](https://discuss.elastic.co/u/AmS)\
**Post date:** [November 13, 2020, 3:00pm UTC](https://discuss.elastic.co/t/add-a-condition-on-ml/255358/1 "2020-11-13T15:00:14Z")

</div>

Hello ,  
I m using ML plugin Kibana 7.4.

I have a question about the following Case:

- We have a list of Event.
- We are reassuring the number of occurrence of these event.
- All the event are important
- But the events are not important if there is specific event that occurs on the middle of a list of events:  
For example :

- the number of event is important if i have the following sequence : X X X X Y Y X X X X Y X X
- the number of event is not important if i have the following sequence : X X X X Y Y X X X X Y X Z X  
Where X Y and Z are my events name.  
The second sequence is not important since that i have and event named Z received in the sequence.

Is it possible to change the score of the ML on this case ? so that we avoid alerting on this case.

Thanks  
Best regards  
Amine S

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [November 16, 2020, 3:11pm UTC](https://discuss.elastic.co/t/add-a-condition-on-ml/255358/2 "2020-11-16T15:11:12Z")

</div>

At what frequency do these events occur? Do they all happen within the same minute? hour? day? Or an unknown, arbitrary time? This will be important, I think because to assess whether or not some kind of event "is in the middle of others", then you'll need to wait until the subsequent events appear or not. How long you need to wait to determine this situation will be important. At this point, I'm not even entirely convinced this is an ML problem - perhaps it can just be solved with a search and a conditional.

---

<div class="post-metadata">

**Author:** ![AmS](https://avatars.discourse-cdn.com/v4/letter/a/a4c791/32.png) [@AmS](https://discuss.elastic.co/u/AmS)\
**Post date:** [November 17, 2020, 2:34pm UTC](https://discuss.elastic.co/t/add-a-condition-on-ml/255358/3 "2020-11-17T14:34:35Z")

</div>

Thanks for your prompt response

1-This event occur when the operator set something manually and often

2- this event happen before 1 to 2 min before the other events occur and I want to ignore all them

3- We have configured a bucket span of 5 minutes

Thanks

---

<div class="post-metadata">

**Author:** ![Merit125](https://avatars.discourse-cdn.com/v4/letter/m/c4cdca/32.png) [@Merit125](https://discuss.elastic.co/u/Merit125)\
**Post date:** [November 21, 2020, 9:10am UTC](https://discuss.elastic.co/t/add-a-condition-on-ml/255358/4 "2020-11-21T09:10:15Z")

</div>

Hi  
I'm also facing the same problem " how to add condition on ML?"  
Thanks

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [November 23, 2020, 4:58pm UTC](https://discuss.elastic.co/t/add-a-condition-on-ml/255358/5 "2020-11-23T16:58:43Z")

</div>

@AmS - I'm still unconvinced this is a use-case best solved by ML. It seems to me that you can solve this use case by using the `sequence` search of [EQL](https://www.elastic.co/guide/en/elasticsearch/reference/current/eql.html). (EQL is available v7.9+)

Something like:

```auto
GET /events/_eql/search
{
  "query": """
    sequence
      [myevent where event.value == "X"]
      [myevent where event.value == "Y"]
      [myevent where event.value == "Z"]
  """
}

```

If the events were

` X X X X Y Y X X X X Y X X` - the above query would return nothing

If the events were

`X X X X Y Y X X X X Y X Z X` - the above query would return the sequence

Then, within an alert (Watch) you could inspect the output of the EQL query and alert accordingly

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [November 23, 2020, 6:54pm UTC](https://discuss.elastic.co/t/add-a-condition-on-ml/255358/6 "2020-11-23T18:54:35Z")

</div>

Here's a simplified example - use DevTools to execute each command in order:

```auto
#create a index of events with necessary mappings
PUT events/
{
  "mappings": {
    "properties": {
      "@timestamp": {
        "type": "date",
        "format": "yyyy-MM-dd HH:mm:ss"
      },
      "event": {
        "properties": {
          "category": {
            "type": "keyword"
          },
          "value": {
            "type": "keyword"
          }
        }
      }
    }
  }
}

PUT events/_doc/1
{
  "@timestamp": "2020-11-23 12:00:00",
  "event.category": "myevent",
  "event.value": "X"
}
PUT events/_doc/2
{
  "@timestamp": "2020-11-23 12:01:00",
  "event.category": "myevent",
  "event.value": "X"
}
PUT events/_doc/3
{
  "@timestamp": "2020-11-23 12:02:00",
  "event.category": "myevent",
  "event.value": "X"
}
PUT events/_doc/4
{
  "@timestamp": "2020-11-23 12:03:00",
  "event.category": "myevent",
  "event.value": "Y"
}
PUT events/_doc/5
{
  "@timestamp": "2020-11-23 12:04:00",
  "event.category": "myevent",
  "event.value": "X"
}
#Try searching the sequence - should see no results
GET /events/_eql/search
{
  "query": """
    sequence
      [myevent where event.value == "X"]
      [myevent where event.value == "Y"]
      [myevent where event.value == "Z"]
  """
}

#Add in the critical event "Z"
PUT events/_doc/6
{
  "@timestamp": "2020-11-23 12:05:00",
  "event.category": "myevent",
  "event.value": "Z"
}
#Try search the sequence again - should now see the sequence returned
GET /events/_eql/search
{
  "query": """
    sequence
      [myevent where event.value == "X"]
      [myevent where event.value == "Y"]
      [myevent where event.value == "Z"]
  """
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 21, 2020, 6:54pm UTC](https://discuss.elastic.co/t/add-a-condition-on-ml/255358/7 "2020-12-21T18:54:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
