# Anomaly detection

**URL:** <https://discuss.elastic.co/t/anomaly-detection/358048>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-machine-learning\
**Created:** [April 23, 2024, 4:36pm UTC](https://discuss.elastic.co/t/anomaly-detection/358048 "2024-04-23T16:36:02Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![zi\_ninja](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zi_ninja/32/133702_2.png) [@zi\_ninja](https://discuss.elastic.co/u/zi_ninja)\
**Post date:** [April 23, 2024, 4:36pm UTC](https://discuss.elastic.co/t/anomaly-detection/358048/1 "2024-04-23T16:36:02Z")

</div>

In machine learning anomaly detection, can I set my own rules for detection?  
Example: I want to detect a computer. Normally this computer accesses many different IP addresses, but suddenly one day this computer accesses a completely new IP address compared to the previous addresses. The previous IP it accessed. So for this action, this is abnormal, but I want to set this rule so that machine learning does not identify this as abnormal-\>normal.

What should I do?

---

<div class="post-metadata">

**Author:** ![valeriy42](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/valeriy42/32/82758_2.png) [@valeriy42](https://discuss.elastic.co/u/valeriy42)\
**Post date:** [May 6, 2024, 3:22pm UTC](https://discuss.elastic.co/t/anomaly-detection/358048/2 "2024-05-06T15:22:59Z")

</div>

Hello @zi_ninja ,

we have rare detectors that can do what you are interested in. Please refer to the details in the blog post [Using Elastic machine learning rare analysis to hunt for the unusual](https://www.elastic.co/blog/using-elastic-machine-learning-rare-analysis-to-hunt-for-the-unusual).  
If you are interested in canonical outlier detection; please check our documentation on [finding outliers](https://www.elastic.co/guide/en/machine-learning/current/ml-dfa-finding-outliers.html).
