# Bucket span in Job management

**URL:** <https://discuss.elastic.co/t/bucket-span-in-job-management/175993>\
**Category:** Kibana\
**Tags:** elastic-stack-machine-learning\
**Created:** [April 9, 2019, 9:21am UTC](https://discuss.elastic.co/t/bucket-span-in-job-management/175993 "2019-04-09T09:21:26Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Prabhav](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/prabhav/32/64630_2.png) [@Prabhav](https://discuss.elastic.co/u/Prabhav)\
**Post date:** [April 9, 2019, 9:21am UTC](https://discuss.elastic.co/t/bucket-span-in-job-management/175993/1 "2019-04-09T09:21:26Z")

</div>

![w](https://us1.discourse-cdn.com/elastic/original/3X/c/5/c5534d162e707d529526781d37dda6a254e1d2a9.png)  
Can someone explain what exactly is happening and how the field,aggregation and bucket span work together?

1. I am not able to get from where exactly the numbers in y-axis are appearing?
2. I cannot get it if the bucket span checks only for the last 5 seconds of the data dumped as elastic response?(basically if someone could explain how the bucket span works with indexed data that would be great)

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [April 9, 2019, 6:37pm UTC](https://discuss.elastic.co/t/bucket-span-in-job-management/175993/2 "2019-04-09T18:37:03Z")

</div>

Relevant blog: [https://www.elastic.co/blog/explaining-the-bucket-span-in-machine-learning-for-elasticsearch](https://www.elastic.co/blog/explaining-the-bucket-span-in-machine-learning-for-elasticsearch)

The values of the y-axis are the sum of the field `V2A7` in 5s increments (in your case). I assume that in your case, these values are negative in value.

---

<div class="post-metadata">

**Author:** ![Prabhav](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/prabhav/32/64630_2.png) [@Prabhav](https://discuss.elastic.co/u/Prabhav)\
**Post date:** [April 10, 2019, 8:43am UTC](https://discuss.elastic.co/t/bucket-span-in-job-management/175993/3 "2019-04-10T08:43:53Z")

</div>

can you please elaborate a bit about in what reference 5s increments are?  
In the link mentioned above it states:-

**For example, if you were monitoring the average response time of a system, using a bucket span of 1 hour means that at the end of each hour we would calculate the average (mean) value of the last hour’s worth of data and compute the anomalousness of that average value compared to previous hours.**  
Can you explain what exactly is "_compute the anomalousness of that average value compared to previous hours_"  
Thanks a lot for your help!

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [April 10, 2019, 12:43pm UTC](https://discuss.elastic.co/t/bucket-span-in-job-management/175993/4 "2019-04-10T12:43:14Z")

</div>

You chose a bucket\_span of `5s`, which I can see in your screenshot. This is why I mentioned it. I'm not saying that this is the correct thing to choose - only just noticed that is what you set

The bucket span is the window of time over which your data is aggregated. So, if you say:

`sum(V2A7)` with a bucket\_span of `5s` then all observed values of field `V2A7` are summed in little 5 second windows over time and that summed value is modeled with ML.

So for example let's imagine a simplified data set:

```auto
time, V2A7
00:00:01, 5
00:00:02, 5
00:00:04, 5
00:00:06, 4
00:00:07, 3
00:00:08, 3
00:00:09, 2
00:00:11, 5
00:00:12, 5
00:00:14, 5
...

```

With a 5s bucket\_span and a `sum()` aggregation, the above data is summed up into 5s intervals:

```auto
00:00:00, 15
00:00:05, 12
00:00:10, 15
...

```

ML then learns these values over time (let's say, for example, that the above value of 12 to 15-ish is usual and repeatable over time). Then, at some later time, the following values occur:

```auto
09:11:00, 15
09:11:05, 240
09:11:10, 15
...

```

The value of `240` will be seen as unusual since it is very different than the typical `sum()` values (which are around 12 to 15)

You should choose your bucket\_span, however, with the tips from the blog. In 99% of the cases in machine data, the value of bucket\_span will likely be measured in minutes, not seconds.

---

<div class="post-metadata">

**Author:** ![Prabhav](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/prabhav/32/64630_2.png) [@Prabhav](https://discuss.elastic.co/u/Prabhav)\
**Post date:** [April 11, 2019, 2:25am UTC](https://discuss.elastic.co/t/bucket-span-in-job-management/175993/5 "2019-04-11T02:25:43Z")

</div>

@richcollier  
Thank you so much for clearing the doubt, example was really helpful.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 9, 2019, 2:30am UTC](https://discuss.elastic.co/t/bucket-span-in-job-management/175993/6 "2019-05-09T02:30:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
