I am trying out the anomaly detection job.
The data is coming from logstash at interval of 5 mins. But sometimes there will be no data in those 5 mins. The data itself will be randomly distrubuted in the 5 min slot. Sometimes there will be 5 data points at start of the time slot. Sometimes in middle. Sometime at end.
Like all these are possible scenarios:
Data at start:
Data in middle:
Data in end:
I have kept the Query delay and Frequency delay to 5m. My idea is to not miss any data.
The suggested Bucket Span was 30m.
Should it not have been 5 mins?