# Keeping anomaly scoring constant

**URL:** <https://discuss.elastic.co/t/keeping-anomaly-scoring-constant/323365>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-machine-learning\
**Created:** [January 17, 2023, 9:21pm UTC](https://discuss.elastic.co/t/keeping-anomaly-scoring-constant/323365 "2023-01-17T21:21:37Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![emi\_rose](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/emi_rose/32/83050_2.png) [@emi\_rose](https://discuss.elastic.co/u/emi_rose)\
**Post date:** [January 17, 2023, 9:21pm UTC](https://discuss.elastic.co/t/keeping-anomaly-scoring-constant/323365/1 "2023-01-17T21:21:37Z")

</div>

Hi there,

I'm currently trying to configure an advanced job that detects low counts or zero counts of documents by using low\_count by field1. I basically want the job to detect any abnormal behavior at all. Some attributes of field1 have more cyclical and predictable behavior than others, which makes them easier to detect abnormal behavior.

I'm finding that the more data the model takes in, the lower the severity the anomalies are scored with. I know this is just the nature of machine learning, but I need some way to continuing alerting on those events with the same level of severity. Is there anything I can do to hold this constant so they are not in the future disregarded as anomalies entirely?

 ![Screen Shot 2023-01-17 at 3.04.56 PM](https://us1.discourse-cdn.com/elastic/original/3X/4/8/485944101de17f705b1857b33d76ef648f81d21e.png)

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [January 17, 2023, 9:51pm UTC](https://discuss.elastic.co/t/keeping-anomaly-scoring-constant/323365/2 "2023-01-17T21:51:43Z")

</div>

Not to get too philosophical, but if you have a situation where the data's behavior is truly predictable like this, then Anomaly Detection isn't the right solution here because anomalies are, by definition, surprise events. So, maybe Just define a traditional alert?

---

<div class="post-metadata">

**Author:** ![emi\_rose](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/emi_rose/32/83050_2.png) [@emi\_rose](https://discuss.elastic.co/u/emi_rose)\
**Post date:** [January 17, 2023, 10:05pm UTC](https://discuss.elastic.co/t/keeping-anomaly-scoring-constant/323365/3 "2023-01-17T22:05:23Z")

</div>

Hi Rich,

Thank you for answering my question. I too was wondering if Anomaly Detection was the right solution for the case. Is there any other alerting system you might recommend for detecting an unexpected lack of data or a zero count then? I was finding that anomaly detection worked well for that but I'm not sure if it's a sustainable option over time.

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [January 18, 2023, 1:16pm UTC](https://discuss.elastic.co/t/keeping-anomaly-scoring-constant/323365/4 "2023-01-18T13:16:34Z")

</div>

> [@Alert when data is missing?](https://discuss.elastic.co/t/alert-when-data-is-missing/307886/4):
>
> You can check the documentation on how to create an alert. Start [here](https://www.elastic.co/guide/en/kibana/current/alerting-getting-started.html), then this shows you how to create an [index threshold rule](https://www.elastic.co/guide/en/kibana/current/rule-type-index-threshold.html) which can help you monitor your index.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 15, 2023, 1:17pm UTC](https://discuss.elastic.co/t/keeping-anomaly-scoring-constant/323365/5 "2023-02-15T13:17:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
