# Anomaly detection rules don't execute provided actions

**URL:** <https://discuss.elastic.co/t/anomaly-detection-rules-dont-execute-provided-actions/300691>\
**Category:** Kibana\
**Created:** [March 25, 2022, 11:33am UTC](https://discuss.elastic.co/t/anomaly-detection-rules-dont-execute-provided-actions/300691 "2022-03-25T11:33:27Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rick\_V](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rick_v/32/131683_2.png) [@Rick\_V](https://discuss.elastic.co/u/Rick_V)\
**Post date:** [March 25, 2022, 11:33am UTC](https://discuss.elastic.co/t/anomaly-detection-rules-dont-execute-provided-actions/300691/1 "2022-03-25T11:33:27Z")

</div>

Hi,

I've got a detection rule set up for a anomaly job, it checks whether in the last 5 minutes an anomaly higher than 50, 75 or 90 was reported and then performs two action: index a document with data such as the score, influencers and timestamp and send a message to a teams channel. tested both connectors and they both work. Still when an anomaly occurs in the data stream, none of the actions are executed. When i check for occurencies on which the rule should reponds, it shows 59 anomalies, still nothing happend on the other side.  
Can someone tell me where to look for the problem?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/e/4e0ab43c3ea0c948a1c9f4b8a222eb2211dea7f5.png)

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [March 28, 2022, 11:44am UTC](https://discuss.elastic.co/t/anomaly-detection-rules-dont-execute-provided-actions/300691/2 "2022-03-28T11:44:54Z")

</div>

First of all, consider upgrading your cluster to a version in which the Alerting is GA, and no longer Beta.

Secondly, what you experience sounds like a situation in which the lookback interval is shorter than the job's bucket\_span. Found under advanced settings. From the [docs](https://www.elastic.co/guide/en/machine-learning/current/ml-configuring-alerts.html):

> _Lookback interval_ sets an interval that is used to query previous anomalies during each condition check. Its value is derived from the bucket span of the job and the query delay of the datafeed by default. It is not recommended to set the lookback interval lower than the default value as it might result in missed anomalies.

So, compare your job's bucket\_span value and the value set for the Lookback interval. The Lookback interval should be 2 times the value of bucket\_span

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 25, 2022, 11:45am UTC](https://discuss.elastic.co/t/anomaly-detection-rules-dont-execute-provided-actions/300691/3 "2022-04-25T11:45:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
