# Extract the results of a ML job

**URL:** <https://discuss.elastic.co/t/extract-the-results-of-a-ml-job/185414>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-machine-learning\
**Created:** [June 12, 2019, 12:28pm UTC](https://discuss.elastic.co/t/extract-the-results-of-a-ml-job/185414 "2019-06-12T12:28:45Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bharath\_Kumar\_R](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bharath_kumar_r/32/45474_2.png) [@Bharath\_Kumar\_R](https://discuss.elastic.co/u/Bharath_Kumar_R)\
**Post date:** [June 12, 2019, 12:28pm UTC](https://discuss.elastic.co/t/extract-the-results-of-a-ml-job/185414/1 "2019-06-12T12:28:46Z")

</div>

Is there any way to extract the results of a ML job(i.e, the detected anomalies in input data) using languages like python with their Elasticsearch client?

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [June 12, 2019, 12:46pm UTC](https://discuss.elastic.co/t/extract-the-results-of-a-ml-job/185414/2 "2019-06-12T12:46:56Z")

</div>

All results from ML jobs are stored in the `.ml-anomalies-*` indices and therefore are accessible via query from any ES client

---

<div class="post-metadata">

**Author:** ![Bharath\_Kumar\_R](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bharath_kumar_r/32/45474_2.png) [@Bharath\_Kumar\_R](https://discuss.elastic.co/u/Bharath_Kumar_R)\
**Post date:** [June 13, 2019, 11:35am UTC](https://discuss.elastic.co/t/extract-the-results-of-a-ml-job/185414/3 "2019-06-13T11:35:46Z")

</div>

I used the following code to fetch the results for the anomaly jobs  
doc = {  
'size' : 10000,  
'query': {  
'match\_all' : {}  
}  
}  
res=es.search(index='.ml-anomalies-\*', body=doc)

I got the following output:

{'\_index': '.ml-anomalies-shared',  
'\_type': '\_doc',  
'\_id': 'abcd\_bucket\_1560420000000\_3600',  
'\_score': 1.0,  
'\_source': {'job\_id': 'abcd',  
'timestamp': 1560420000000,  
'anomaly\_score': 0.0,  
'bucket\_span': 3600,  
'initial\_anomaly\_score': 0.0,  
'event\_count': 68,  
'is\_interim': True,  
'bucket\_influencers': ,  
'processing\_time\_ms': 2,  
'result\_type': 'bucket'}

When I tried to convert the timestamp to date time format, I get the below error:  
----\> 1 dt=datetime.fromtimestamp(1560420000000)

ValueError: year 51417 is out of range

In what format does the .ml-anomalies-\* index store the timestamp value? Is any formatting needed for the timestamp values returned to get the correct date and time?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 13, 2019, 11:38am UTC](https://discuss.elastic.co/t/extract-the-results-of-a-ml-job/185414/4 "2019-06-13T11:38:44Z")

</div>

Does this help?

> Internally, dates are converted to UTC (if the time-zone is specified) and stored as a long number representing milliseconds-since-the-epoch.

> **[Date datatype | Elasticsearch Guide \[7.1\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.1/date.html)**

You should be able to convert from that.

---

<div class="post-metadata">

**Author:** ![Bharath\_Kumar\_R](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bharath_kumar_r/32/45474_2.png) [@Bharath\_Kumar\_R](https://discuss.elastic.co/u/Bharath_Kumar_R)\
**Post date:** [June 13, 2019, 11:42am UTC](https://discuss.elastic.co/t/extract-the-results-of-a-ml-job/185414/5 "2019-06-13T11:42:23Z")

</div>

Thank you, I resolved the issue now. I just divided the timestamp by 1000 as it was in milliseconds

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [June 13, 2019, 12:01pm UTC](https://discuss.elastic.co/t/extract-the-results-of-a-ml-job/185414/6 "2019-06-13T12:01:32Z")

</div>

Notice that inside the result index, there are a variety of different documents, each with their own usefulness

`result_type:bucket`  
`result_type:record`  
`result_type:influencer`

More info here: [https://www.elastic.co/blog/machine-learning-anomaly-scoring-elasticsearch-how-it-works](https://www.elastic.co/blog/machine-learning-anomaly-scoring-elasticsearch-how-it-works)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 11, 2019, 12:01pm UTC](https://discuss.elastic.co/t/extract-the-results-of-a-ml-job/185414/7 "2019-07-11T12:01:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
