# Anomaly Detection Categorization: Kibana Signs used for Severities(warning, minor, major, critical)

**URL:** <https://discuss.elastic.co/t/anomaly-detection-categorization-kibana-signs-used-for-severities-warning-minor-major-critical/303039>\
**Category:** Kibana\
**Tags:** elastic-stack-machine-learning\
**Created:** [April 22, 2022, 1:29pm UTC](https://discuss.elastic.co/t/anomaly-detection-categorization-kibana-signs-used-for-severities-warning-minor-major-critical/303039 "2022-04-22T13:29:49Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![aviral\_srivastava](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aviral_srivastava/32/98018_2.png) [@aviral\_srivastava](https://discuss.elastic.co/u/aviral_srivastava)\
**Post date:** [April 22, 2022, 1:29pm UTC](https://discuss.elastic.co/t/anomaly-detection-categorization-kibana-signs-used-for-severities-warning-minor-major-critical/303039/1 "2022-04-22T13:29:49Z")

</div>

Hi,

I am using Elasticsearch 8.1.0 and kibana 8.1.0  
I have created a Categorization job in kibana. As input, I have given the index field which contains the log messages.

After the job gets completed processing, I can see the Analysis results at the bottom in tabular format

I can see ml categories are divided into 4 types of severity: warning, minor, major and critical.  
warning represented by grey dot  
minor represented by yellow dot  
major represented by orange dot  
critical represented by red dot

But also somewhere plus sign appears. Why do they mean?

 ![categorization](https://us1.discourse-cdn.com/elastic/original/3X/8/8/88c384039ff7884d421de9e97a3c72c610c9909d.png)

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [April 22, 2022, 3:31pm UTC](https://discuss.elastic.co/t/anomaly-detection-categorization-kibana-signs-used-for-severities-warning-minor-major-critical/303039/2 "2022-04-22T15:31:49Z")

</div>

see: [Interpreting multi-bucket impact anomalies using Elastic machine learning features | Elastic Blog](https://www.elastic.co/blog/interpreting-multi-bucket-impact-anomalies-using-elastic-machine-learning-features)

---

<div class="post-metadata">

**Author:** ![aviral\_srivastava](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aviral_srivastava/32/98018_2.png) [@aviral\_srivastava](https://discuss.elastic.co/u/aviral_srivastava)\
**Post date:** [April 25, 2022, 4:47pm UTC](https://discuss.elastic.co/t/anomaly-detection-categorization-kibana-signs-used-for-severities-warning-minor-major-critical/303039/3 "2022-04-25T16:47:24Z")

</div>

Thanks for the blog post.  
It really helped.

In my case I have given the message field as an input to the anomaly detector job which only contains log messages. So ML has created 15 different categories out of it.

So, in the multi-bucket impact anomaly, do the anomalies in previous 11 buckets should belong to the same ml category? or they could be different ml category?

I have a ml category, which is marked with a cross. So does this mean there were ml categories which showed anomalous behaviour in the previous 11 buckets, not necessarily the same ml category?

Also, can we have a multi-bucket impact anomaly if in the previous 11 buckets some have anomalous behaviour while some do not?

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [April 25, 2022, 6:41pm UTC](https://discuss.elastic.co/t/anomaly-detection-categorization-kibana-signs-used-for-severities-warning-minor-major-critical/303039/4 "2022-04-25T18:41:13Z")

</div>

A Multi-bucket anomaly means a particular entity (in your case `ml_category`) had an anomaly with respect to a longer timeframe (not a single bucket of time). It does not mean that other entities also had an anomaly. The purpose of a multi-bucket anomaly is to find that trend that looks over a longer period of time (a sliding window of 12 bucket\_spans) rather than individual bucket\_spans.

To explicitly answer your questions:

> So, in the multi-bucket impact anomaly, do the anomalies in previous 11 buckets should belong to the same ml category? or they could be different ml category?

Yes, the same `ml_category`

> I have a ml category, which is marked with a cross. So does this mean there were ml categories which showed anomalous behaviour in the previous 11 buckets, not necessarily the same ml category?

No.

---

<div class="post-metadata">

**Author:** ![aviral\_srivastava](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aviral_srivastava/32/98018_2.png) [@aviral\_srivastava](https://discuss.elastic.co/u/aviral_srivastava)\
**Post date:** [April 26, 2022, 5:59am UTC](https://discuss.elastic.co/t/anomaly-detection-categorization-kibana-signs-used-for-severities-warning-minor-major-critical/303039/5 "2022-04-26T05:59:51Z")

</div>

Thanks for the reply. It helped.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 24, 2022, 6:00am UTC](https://discuss.elastic.co/t/anomaly-detection-categorization-kibana-signs-used-for-severities-warning-minor-major-critical/303039/6 "2022-05-24T06:00:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
