Anomaly Detection on high-dimensionality data


The anomaly detection features in x-pack look awesome. I was wondering, though - if my data has a dimension (let's say country) with a cardinality of 150 - do I have to make 150 separate metrics to see anomalies for individual countries, or can I create one metric, and let the software surface a particular country with an anomaly?


There is a lot of useful examples and links available in this GitHub repo. Based on your description it sounds like you may want to configure a multi-metric job, so that may be a good starting point.

