# Forecast still works on a machine that is not being monitored anymore

**URL:** <https://discuss.elastic.co/t/forecast-still-works-on-a-machine-that-is-not-being-monitored-anymore/266004>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-machine-learning\
**Created:** [March 2, 2021, 6:40pm UTC](https://discuss.elastic.co/t/forecast-still-works-on-a-machine-that-is-not-being-monitored-anymore/266004 "2021-03-02T18:40:52Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![ElasticLiver](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elasticliver/32/64869_2.png) [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Post date:** [March 2, 2021, 6:40pm UTC](https://discuss.elastic.co/t/forecast-still-works-on-a-machine-that-is-not-being-monitored-anymore/266004/1 "2021-03-02T18:40:53Z")

</div>

I have a machine that is not being monitored anymore, since 15 january. but I can still do a forecast, is there a way to handle this? other than to do a delete by query on the ML index?

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [March 2, 2021, 7:30pm UTC](https://discuss.elastic.co/t/forecast-still-works-on-a-machine-that-is-not-being-monitored-anymore/266004/2 "2021-03-02T19:30:08Z")

</div>

Handle what exactly? Your question is not very clear. Please elaborate.

---

<div class="post-metadata">

**Author:** ![ElasticLiver](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elasticliver/32/64869_2.png) [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Post date:** [March 2, 2021, 8:22pm UTC](https://discuss.elastic.co/t/forecast-still-works-on-a-machine-that-is-not-being-monitored-anymore/266004/3 "2021-03-02T20:22:14Z")

</div>

how to not include from forecast the machines that are not being monitored anymore, the ones that do not receive data, because even if you dont get data for two month you can do a forecast.

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [March 2, 2021, 9:08pm UTC](https://discuss.elastic.co/t/forecast-still-works-on-a-machine-that-is-not-being-monitored-anymore/266004/4 "2021-03-02T21:08:12Z")

</div>

Ah okay - now I understand. So really, the model needs to be pruned to forget those entities that don't need to be modeled anymore.

I could be wrong, but I think that the only way to manually invoke a pruning of the model is to [close](https://www.elastic.co/guide/en/elasticsearch/reference/7.11/ml-close-job.html) the job and then re-open it.

> When you close a job, it runs housekeeping tasks such as pruning the model history, flushing buffers, calculating final results and persisting the model snapshots. Depending upon the size of the job, it could take several minutes to close and the equivalent time to re-open.

Perhaps you could give that a try?

---

<div class="post-metadata">

**Author:** ![ElasticLiver](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elasticliver/32/64869_2.png) [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Post date:** [March 2, 2021, 9:53pm UTC](https://discuss.elastic.co/t/forecast-still-works-on-a-machine-that-is-not-being-monitored-anymore/266004/5 "2021-03-02T21:53:02Z")

</div>

Didnt work, closed the job an re-opened it, but still creates a forecast

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/f/5f8c8a25c8977107b7b8001405a86c154d87afa2.png)

I guess the only solution left is delete by query

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [March 3, 2021, 12:04pm UTC](https://discuss.elastic.co/t/forecast-still-works-on-a-machine-that-is-not-being-monitored-anymore/266004/6 "2021-03-03T12:04:33Z")

</div>

I see - that's unfortunate. Well, delete-by-query isn't practical either as references to the entities are intertwined in large state documents in `.ml-state`

The only practical answer at this point is to either:

a) continue as-is, but build a mechanism to ignore the forecasts for entities that don't exist anymore  
b) clone the job and start over, being sure to only look back in time long enough to get some good historical learning, but not too far back to pick up references to entities that you no longer want.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 31, 2021, 12:04pm UTC](https://discuss.elastic.co/t/forecast-still-works-on-a-machine-that-is-not-being-monitored-anymore/266004/7 "2021-03-31T12:04:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
