# Anomaly detection job failing to pull any data in

**URL:** <https://discuss.elastic.co/t/anomaly-detection-job-failing-to-pull-any-data-in/268940>\
**Category:** Elasticsearch\
**Created:** [March 31, 2021, 5:45pm UTC](https://discuss.elastic.co/t/anomaly-detection-job-failing-to-pull-any-data-in/268940 "2021-03-31T17:45:32Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![timothyhutz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timothyhutz/32/86409_2.png) [@timothyhutz](https://discuss.elastic.co/u/timothyhutz)\
**Post date:** [March 31, 2021, 5:45pm UTC](https://discuss.elastic.co/t/anomaly-detection-job-failing-to-pull-any-data-in/268940/1 "2021-03-31T17:45:32Z")

</div>

So our ingestion mechanism for ingesting data had stopped for an hour, now my machine learning jobs refuse to pull in any new documents. I have verified it can see new latest document dates but just doesn't pull them in or do any analysis them. It also alerting that it has seen any new documents when the ingestion stopped, but now still won't take any of the new documents that I know for a fact are getting ingested and showing up in search. How do I make the ML jobs start taking the documents in? I already restarted the data-feed.

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [April 1, 2021, 6:00pm UTC](https://discuss.elastic.co/t/anomaly-detection-job-failing-to-pull-any-data-in/268940/2 "2021-04-01T18:00:48Z")

</div>

The ML job, by default, will not go "back in time" to re-process bucket\_spans that have already been analyzed.

You can, however, [figure out the last model snapshot](https://www.elastic.co/guide/en/elasticsearch/reference/7.12/ml-get-snapshot.html) taken before your ingest outage, [revert](https://www.elastic.co/guide/en/elasticsearch/reference/7.12/ml-revert-snapshot.html) to that snapshot, and delete the intervening results.

Then, just restart the datafeed from the point of the time of the snapshot and continue live.

This is possible via the UI in recent versions (I think v7.11+) from the Jobs Management page

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/8/a8fb9bd2d66008660f3bc534aaecf9ecfb15eec6.png)

---

<div class="post-metadata">

**Author:** ![timothyhutz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timothyhutz/32/86409_2.png) [@timothyhutz](https://discuss.elastic.co/u/timothyhutz)\
**Post date:** [April 7, 2021, 7:37pm UTC](https://discuss.elastic.co/t/anomaly-detection-job-failing-to-pull-any-data-in/268940/3 "2021-04-07T19:37:17Z")

</div>

So my question is why does the datafeed just stop loading any future data it gets on time? do I need to delay my data query delay far enough back?

---

<div class="post-metadata">

**Author:** ![timothyhutz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timothyhutz/32/86409_2.png) [@timothyhutz](https://discuss.elastic.co/u/timothyhutz)\
**Post date:** [April 7, 2021, 7:38pm UTC](https://discuss.elastic.co/t/anomaly-detection-job-failing-to-pull-any-data-in/268940/4 "2021-04-07T19:38:19Z")

</div>

anotherwords it just stops loading data altogether if it hits a period of no data.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 5, 2021, 7:38pm UTC](https://discuss.elastic.co/t/anomaly-detection-job-failing-to-pull-any-data-in/268940/5 "2021-05-05T19:38:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
