# Kibana Machine Learning Job Alert

**URL:** <https://discuss.elastic.co/t/kibana-machine-learning-job-alert/339151>\
**Category:** Kibana\
**Tags:** elastic-stack-machine-learning\
**Created:** [July 25, 2023, 7:03am UTC](https://discuss.elastic.co/t/kibana-machine-learning-job-alert/339151 "2023-07-25T07:03:25Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Aniket\_Pant](https://avatars.discourse-cdn.com/v4/letter/a/77aa72/32.png) [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Post date:** [July 25, 2023, 7:03am UTC](https://discuss.elastic.co/t/kibana-machine-learning-job-alert/339151/1 "2023-07-25T07:03:25Z")

</div>

Hi Team,

We have created alert for anomaly detection and we are getting this alert on email.  
It is showing different timestamp

```auto
Elastic Stack Machine Learning Alert:
- Job IDs: {{context.jobIds}}
- Time: {{context.timestampIso8601}}
- Anomaly score: {{context.score}}

{{context.message}}
{{#context.topInfluencers.length}}
  Top influencers:
  {{#context.topInfluencers}}
    {{influencer_field_name}} = {{influencer_field_value}} [{{score}}]
  {{/context.topInfluencers}}
{{/context.topInfluencers.length}}

{{#context.topRecords.length}}
  Top records:
  {{#context.topRecords}}
    {{function}}({{field_name}}) {{by_field_value}} {{over_field_value}} {{partition_field_value}} [{{score}}]
  {{/context.topRecords}}
{{/context.topRecords.length}}

{{! Replace kibanaBaseUrl if not configured in Kibana }}
[Open in Anomaly Explorer]({{{kibanaBaseUrl}}}{{{context.anomalyExplorerUrl}}})

```

Result in the email

```auto
Elastic Stack Machine Learning Alert:
•	Job IDs: agg-pss-ist-awesant
•	Time: 2023-07-24T10:00:00.000Z
•	Anomaly score: 85

Alerts are raised based on real-time scores. Remember that scores may be adjusted over time as data continues to be analyzed.

Top influencers: PCode.keyword = 011000 [97] Destination.keyword = 549627 [97] Source.keyword = 0093 [97]

Top records: max(hits) [85]

```

Anomaly was detected at 15:30-15:35 but it is showing different time  
i have shared screenshot for this . I would like to know in the screenshot it is showing `July 24th 2023, 15:00` (highlighted part) but in the table it is showing actual timerange. Can you please tell me also on this part

 ![ml2](https://us1.discourse-cdn.com/elastic/original/3X/f/c/fc85ffebae851044dee9961ad1c9ddc2fef41bcd.png)

---

<div class="post-metadata">

**Author:** ![darnautov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/darnautov/32/70608_2.png) [@darnautov](https://discuss.elastic.co/u/darnautov)\
**Post date:** [July 25, 2023, 8:22am UTC](https://discuss.elastic.co/t/kibana-machine-learning-job-alert/339151/2 "2023-07-25T08:22:46Z")

</div>

Hi @Aniket_Pant ,

Could you please share complete configuration details of your anomaly detection job and alerting rule as well? There are several important factors define the alerting context, e.g. what result type is configured in alerting rule, lookback interval, etc. If it's a bucket result, then you receive a timestamp of beginning of the anomalous bucket. The timestamp on the screenshot you shared belongs to the anomaly record. It's the most anomalous records within the lookback interval you configured in your alerting rule.

You can read more about alerting configuration for anomaly detection jobs in this [blog post](https://www.elastic.co/blog/accelerate-actions-on-anomaly-detection-jobs-with-the-kibana-alerting-framework). Hope it helps.

---

<div class="post-metadata">

**Author:** ![Aniket\_Pant](https://avatars.discourse-cdn.com/v4/letter/a/77aa72/32.png) [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Post date:** [July 25, 2023, 8:39am UTC](https://discuss.elastic.co/t/kibana-machine-learning-job-alert/339151/3 "2023-07-25T08:39:38Z")

</div>

> **Summary**
>
> This text will be hidden

```auto
{
  "job_id": "some_job_id",
  "job_type": "anomaly_detector",
  "job_version": "7.17.5",
  "create_time": 1689751050137,
  
    },
    "query": {
      "bool": {
        "filter": [
          {
            "bool": {
              "must": [
                {
                  "term": {
                    "status.keyword": "value"
                  }
                },
                {
                  "term": {
                    "status_1.keyword": "value"
                  }
                },
                {
                  "term": {
                    "aggrType.keyword": "5m"
                  }
                }
"description": "detecting anomaly for business decline",
  "analysis_config": {
    "bucket_span": "5m",
    "detectors": [
      {
        "detector_description": "max(hits)",
        "function": "max",
        "field_name": "hits",
        "detector_index": 0
      }
    ],
    "influencers": [
      "Source.keyword",
      "Destination.keyword",
      "PCode.keyword"
    ]
  },
  "analysis_limits": {
    "model_memory_limit": "11mb",
    "categorization_examples_limit": 4
  },
  "data_description": {
    "time_field": "@timestamp",
    "time_format": "epoch_ms"
  },
 "alerting_rules": [
    {
      "id": "8c13cf80-26c7-11ee-8bf5-9f9a21848a63",
      "notifyWhen": "onActionGroupChange",
      "consumer": "alerts",
      "tags": [
        "aggr-pss-ist-awesant",
        "anomaly detection"
      ],
      "name": "Business Decline Alert",
      "enabled": true,
      "throttle": null,
      "alertTypeId": "xpack.ml.anomaly_detection_alert",
      "apiKeyOwner": "lc5684231",
      "createdBy": "lc5684231",
      "updatedBy": "lc5684231",
      "muteAll": false,
      "mutedInstanceIds": [],
      "schedule": {
        "interval": "5m"
      },
      "actions": [
        {
          "group": "anomaly_score_match",
          "params": {
            "documents": [
              {
                "message": "{{context.metric}}",
                "rule_id": "{{rule.id}}",
                "reason": "{{context.reason}}",
                "timestamp": "{{context.timestamp}}"
              }
            ]
          },
          "actionTypeId": ".index",
          "id": "0ded0760-26c3-11ee-8bf5-9f9a21848a63"
        },
        {
          "group": "anomaly_score_match",
          "params": {
            "message": """Elastic Stack Machine Learning Alert:
- Job IDs: {{context.jobIds}}
- Time: {{context.timestampIso8601}}
- Anomaly score: {{context.score}}

{{context.message}}

{{#context.topInfluencers.length}}
  Top influencers:
  {{#context.topInfluencers}}
    {{influencer_field_name}} = {{influencer_field_value}} [{{score}}]
  {{/context.topInfluencers}}
{{/context.topInfluencers.length}}

{{#context.topRecords.length}}
  Top records:
  {{#context.topRecords}}
    {{function}}({{field_name}}) {{by_field_value}} {{over_field_value}} {{partition_field_value}} [{{score}}]
  {{/context.topRecords}}
{{/context.topRecords.length}}

{{! Replace kibanaBaseUrl if not configured in Kibana }}
[Open in Anomaly Explorer]({{{kibanaBaseUrl}}}{{{context.anomalyExplorerUrl}}})
""",
            "to": [
              "xx.com",
              "xx.com"
            ],
            "subject": "Anomaly Detection For Business Decline"
          },
          "actionTypeId": ".email",
 

```

Hi @darnautov

---

<div class="post-metadata">

**Author:** ![Aniket\_Pant](https://avatars.discourse-cdn.com/v4/letter/a/77aa72/32.png) [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Post date:** [July 27, 2023, 6:24am UTC](https://discuss.elastic.co/t/kibana-machine-learning-job-alert/339151/4 "2023-07-27T06:24:52Z")

</div>

Hi Team,

Can you please me in easier terms that if anomaly was detected at 00:10 AM - 00:15 AM. But in Single metric Explore If we Anomaly detection table in time field column it shows 00:00 please see the below screenshot. It has to show when anomaly was detected. Please see the highlighted part

 ![Screenshot-5](https://us1.discourse-cdn.com/elastic/original/3X/7/2/7230729548561b53acc574c8c89a15b0e9a6e0fe.png)

---

<div class="post-metadata">

**Author:** ![Aniket\_Pant](https://avatars.discourse-cdn.com/v4/letter/a/77aa72/32.png) [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Post date:** [July 28, 2023, 4:59am UTC](https://discuss.elastic.co/t/kibana-machine-learning-job-alert/339151/5 "2023-07-28T04:59:14Z")

</div>

Hi Team,

Can you please help me

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [July 28, 2023, 6:03pm UTC](https://discuss.elastic.co/t/kibana-machine-learning-job-alert/339151/6 "2023-07-28T18:03:34Z")

</div>

Click on the dropdown box labeled "Interval" and select "Show all".

When set to Auto, the table will collapse anomalies that appear in consecutive buckets into a single row.

---

<div class="post-metadata">

**Author:** ![Aniket\_Pant](https://avatars.discourse-cdn.com/v4/letter/a/77aa72/32.png) [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Post date:** [July 31, 2023, 12:06pm UTC](https://discuss.elastic.co/t/kibana-machine-learning-job-alert/339151/7 "2023-07-31T12:06:23Z")

</div>

Hi @richcollier ,  
With "Show all" it is showing correct timestamp

> When set to Auto, the table will collapse anomalies that appear in consecutive buckets into a single row

Could you please explain me in a simple terms

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [July 31, 2023, 2:38pm UTC](https://discuss.elastic.co/t/kibana-machine-learning-job-alert/339151/8 "2023-07-31T14:38:56Z")

</div>

If set to Auto, it will aggregate the anomalies and show a summary in the table (it will aggregate them based on time and offending entity) - showing the max anomaly score for each interval/entity.

See another post about this topic.

> [@Why the number of anomalies in the plot differ from the one in the page("Rows per page")?](https://discuss.elastic.co/t/why-the-number-of-anomalies-in-the-plot-differ-from-the-one-in-the-page-rows-per-page/196335):
>
> Hi I am using the X-Pack. Why there are 5 anomalies in the plot and only 2 in the page ("Rows per page")? What do the red circles mean and what do the red addition symbols mean? By the way, the 2 anomalies that are shown in the page ("Rows per page") match 2 of the red addition symbols in the plot?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 28, 2023, 2:39pm UTC](https://discuss.elastic.co/t/kibana-machine-learning-job-alert/339151/9 "2023-08-28T14:39:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
