# Cant access machine learning index from Canvas

**URL:** <https://discuss.elastic.co/t/cant-access-machine-learning-index-from-canvas/257119>\
**Category:** Kibana\
**Tags:** canvas\
**Created:** [November 30, 2020, 7:29pm UTC](https://discuss.elastic.co/t/cant-access-machine-learning-index-from-canvas/257119 "2020-11-30T19:29:18Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Incauto](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/incauto/32/60149_2.png) [@Incauto](https://discuss.elastic.co/u/Incauto)\
**Post date:** [November 30, 2020, 7:29pm UTC](https://discuss.elastic.co/t/cant-access-machine-learning-index-from-canvas/257119/1 "2020-11-30T19:29:18Z")

</div>

Hi, Im trying to display data from the .ml-anomalies-\* index on Canvas, but it doesnt show the values in the metric visualization. (the index pattern exists)

```auto
SELECT COUNT(*) as count_documents FROM ".ml-anomalies-*" WHERE
anomaly_score > 75 AND job_id = 'my-job 

```

when I run the query I get data  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/e/6e8fececa7e565ef31ce024082a471ee6e5d8e25.png)

then I use the field that I need in the visualization

![image](https://us1.discourse-cdn.com/elastic/original/3X/6/3/634f58ff140e6d3f9b7b9a4a28bdc4b4d02e8d70.png)

but I dont get the value displayed

![image](https://us1.discourse-cdn.com/elastic/original/3X/2/d/2d10b7d9c7eeccd27ebeb3370021931c791f4db6.png)

what is the problem here?

Elastic 7.5

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [December 1, 2020, 3:19pm UTC](https://discuss.elastic.co/t/cant-access-machine-learning-index-from-canvas/257119/2 "2020-12-01T15:19:43Z")

</div>

Pretty sure you need the `math` function:

```auto
filters
  | essql 
  query="SELECT COUNT(*) as count_documents FROM \".ml-anomalies-*\" WHERE anomaly_score > 75 AND job_id = 'farequote_demo'"
  | math "count_documents"
  | metric "anomalies" 
    metricFont={font size=48 family="'Open Sans', Helvetica, Arial, sans-serif" color="#000000" align="center" lHeight=48} 
    labelFont={font size=14 family="'Open Sans', Helvetica, Arial, sans-serif" color="#000000" align="center"}
    metricFormat="0,0.[000]"
  | render

```

Yields:

![image](https://us1.discourse-cdn.com/elastic/original/3X/c/7/c70621a94986261a93e61f31be6317d44c169ec8.png)

---

<div class="post-metadata">

**Author:** ![Incauto](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/incauto/32/60149_2.png) [@Incauto](https://discuss.elastic.co/u/Incauto)\
**Post date:** [December 1, 2020, 4:41pm UTC](https://discuss.elastic.co/t/cant-access-machine-learning-index-from-canvas/257119/3 "2020-12-01T16:41:34Z")

</div>

Hi Rich, I have the math function

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/d/fdc88030a0a54aebdf1b0ca81242fae462883d9f.png)

There is no known issues on canvas accessing the system indices? is the only thing that I can think of....

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [December 1, 2020, 5:13pm UTC](https://discuss.elastic.co/t/cant-access-machine-learning-index-from-canvas/257119/4 "2020-12-01T17:13:21Z")

</div>

No, my example is from a Canvas workpad that is running that exact query to `.ml-anomalies-*`

Do you have a time filter on your Canvas workpad (on any of the panels, not just the visible one) that is limiting the scope of your query to a certain date range where there are no actual anomalies?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/7/277591b24c2d98e75b2c8f032365824b865cb08d.png)

---

<div class="post-metadata">

**Author:** ![Incauto](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/incauto/32/60149_2.png) [@Incauto](https://discuss.elastic.co/u/Incauto)\
**Post date:** [December 1, 2020, 8:42pm UTC](https://discuss.elastic.co/t/cant-access-machine-learning-index-from-canvas/257119/5 "2020-12-01T20:42:12Z")

</div>

I have anomalies in the last 7 days

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/b/fb513fee0ccfd689bf263bcf0d5360cede7652b5.png)

I just have a time filter element in the canvas set to 7 days and still nothing is showing,

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/8/587239cb9050f7020e79a538d721e15cf82a1938.png)  
The strange thing is if I remove the time filter element from the canvas the metric works....so the problem seems to be the time filter...  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/6/76a6288a77fe406b54d17163e72663f41e1a745b.png)  
Maybe because the time field in the .ml-anomalies-\* index is "timestamp" not "@timestamp" like in a regular index?, maybe the time filter doesnt recognize the field?

the problem is that I need the time filter in the canvas

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [December 1, 2020, 11:52pm UTC](https://discuss.elastic.co/t/cant-access-machine-learning-index-from-canvas/257119/6 "2020-12-01T23:52:19Z")

</div>

Ah yes, that's the issue. You could perhaps investigate creating a [field alias](https://www.elastic.co/guide/en/elasticsearch/reference/7.5/alias.html) in the `.ml-anomalies-*` index to map `timestamp` to an alias field called `@timestamp`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 29, 2020, 11:52pm UTC](https://discuss.elastic.co/t/cant-access-machine-learning-index-from-canvas/257119/7 "2020-12-29T23:52:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
