# Is it possible use anomaly detection as query?

**URL:** <https://discuss.elastic.co/t/is-it-possible-use-anomaly-detection-as-query/219666>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-machine-learning\
**Created:** [February 17, 2020, 6:00pm UTC](https://discuss.elastic.co/t/is-it-possible-use-anomaly-detection-as-query/219666 "2020-02-17T18:00:16Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![tfe2012](https://avatars.discourse-cdn.com/v4/letter/t/49beb7/32.png) [@tfe2012](https://discuss.elastic.co/u/tfe2012)\
**Post date:** [February 17, 2020, 6:00pm UTC](https://discuss.elastic.co/t/is-it-possible-use-anomaly-detection-as-query/219666/1 "2020-02-17T18:00:16Z")

</div>

Hi  
I have log index with mapping like this:  
{  
"responseCode",  
"time",  
"serverName"  
}  
If I look to server respose code statistic  
graph like this:

 ![Screen Shot 2020-02-17 at 19.46.06](https://us1.discourse-cdn.com/elastic/original/3X/d/f/df6f9a9c880636a92147c4ca627c09c84dea6dc8.png)

Green: 404, Blue: 200  
Is it possible to use ML algorithm for query:

I want to send a request like:

{  
query: {  
"term": {  
"serverName": "server23456",  
"responseCode": 200  
}  
}  
}

And get a response like this:

"time From: 9:40 - 10:20"

 ![Screen Shot 2020-02-17 at 19.59.58](https://us1.discourse-cdn.com/elastic/original/3X/a/d/adb6db7e5ff9d061bc2791a1eefe568a208d65c0.png)

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [February 18, 2020, 1:43pm UTC](https://discuss.elastic.co/t/is-it-possible-use-anomaly-detection-as-query/219666/2 "2020-02-18T13:43:54Z")

</div>

Within Elastic ML, you always have the ability to configure your anomaly detection jobs to either use all docs in the index, or to use a filtered query. It sounds like you want to use a filtered query.

To accomplish, the easiest way to do this is to build your filtered search in Kibana Discover tab, then save the query with a name. When configuring the ML job, use the named "saved search" as the basis for the ML job.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 17, 2020, 1:44pm UTC](https://discuss.elastic.co/t/is-it-possible-use-anomaly-detection-as-query/219666/3 "2020-03-17T13:44:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
