# Can't understand ML plugin Functionalities

**URL:** <https://discuss.elastic.co/t/cant-understand-ml-plugin-functionalities/125973>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-machine-learning\
**Created:** [March 28, 2018, 4:55pm UTC](https://discuss.elastic.co/t/cant-understand-ml-plugin-functionalities/125973 "2018-03-28T16:55:53Z")\
**Posts on this page:** 1\
**Showing post:** 6

<div class="post-metadata">

**Author:** ![Peter\_Harverson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/peter_harverson/32/21057_2.png) [@Peter\_Harverson](https://discuss.elastic.co/u/Peter_Harverson)\
**Post date:** [March 29, 2018, 2:45pm UTC](https://discuss.elastic.co/t/cant-understand-ml-plugin-functionalities/125973/6 "2018-03-29T14:45:06Z")

</div>

Hi,

The values shown in the expanded row of the anomalies table in the Single Metric Viewer are the typical and actual values observed for the mean(hdopDevice) aggregation used in your detector, over the 30 minute bucket span of your job. It's usually best to ensure the aggregation interval used for plotting the chart matches the bucket span of the job - which you can do by clicking the 'auto' zoom link on the top left of the chart.

As @Badger pointed out, the different components in the Anomaly Explorer view display scores from the various result types. As well as the [link](https://discuss.elastic.co/t/problems-understanding-anomaly-explorer/104266) mentioned, this [blog](https://www.elastic.co/blog/machine-learning-anomaly-scoring-elasticsearch-how-it-works) contains more details on how the anomaly scoring works.

Hope this helps,  
Pete

---

_[View the full topic](https://discuss.elastic.co/t/cant-understand-ml-plugin-functionalities/125973)._
