# \[Agent-Netflow\] Anomaly Detect for spikes on coms between 2 IP

**URL:** <https://discuss.elastic.co/t/agent-netflow-anomaly-detect-for-spikes-on-coms-between-2-ip/335542>\
**Category:** SIEM\
**Created:** [June 8, 2023, 1:51pm UTC](https://discuss.elastic.co/t/agent-netflow-anomaly-detect-for-spikes-on-coms-between-2-ip/335542 "2023-06-08T13:51:11Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![Apoorva\_Joshi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/apoorva_joshi/32/78646_2.png) [@Apoorva\_Joshi](https://discuss.elastic.co/u/Apoorva_Joshi)\
**Post date:** [June 8, 2023, 8:11pm UTC](https://discuss.elastic.co/t/agent-netflow-anomaly-detect-for-spikes-on-coms-between-2-ip/335542/4 "2023-06-08T20:11:24Z")

</div>

Could you please verify the mapping for the source.ip field in the data view you're running the Anomaly Detection on?

It is possible that the source.ip field in your data is mapped as text or some other non-aggregatable type. [Here](https://discuss.elastic.co/t/how-to-make-a-field-aggregatable-in-kibana/90470)'s a link to another Discuss issue that talks about that specific error, and ways to tackle it.

---

_[View the full topic](https://discuss.elastic.co/t/agent-netflow-anomaly-detect-for-spikes-on-coms-between-2-ip/335542)._
