# Log Rate Spikes alert

**URL:** <https://discuss.elastic.co/t/log-rate-spikes-alert/377394>\
**Category:** Elastic Observability\
**Created:** [April 22, 2025, 6:08pm UTC](https://discuss.elastic.co/t/log-rate-spikes-alert/377394 "2025-04-22T18:08:45Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![erikg](https://avatars.discourse-cdn.com/v4/letter/e/91b2a8/32.png) [@erikg](https://discuss.elastic.co/u/erikg)\
**Post date:** [April 22, 2025, 6:08pm UTC](https://discuss.elastic.co/t/log-rate-spikes-alert/377394/1 "2025-04-22T18:08:45Z")

</div>

Hello,  
If I want to build an rule to alert me once a data source has a spike in the data, would the choice be to use ML job ? Or is there already something pre built for this?

---

<div class="post-metadata">

**Author:** ![jessgarson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jessgarson/32/129841_2.png) [@jessgarson](https://discuss.elastic.co/u/jessgarson)\
**Post date:** [April 25, 2025, 6:12pm UTC](https://discuss.elastic.co/t/log-rate-spikes-alert/377394/2 "2025-04-25T18:12:34Z")

</div>

Hi, @erikg,

Good to hear from you again. Would something like what's described [here](https://www.elastic.co/docs/explore-analyze/machine-learning/machine-learning-in-kibana/xpack-ml-aiops) work for you?

Thanks!

Jessica

---

<div class="post-metadata">

**Author:** ![erikg](https://avatars.discourse-cdn.com/v4/letter/e/91b2a8/32.png) [@erikg](https://discuss.elastic.co/u/erikg)\
**Post date:** [April 25, 2025, 6:20pm UTC](https://discuss.elastic.co/t/log-rate-spikes-alert/377394/3 "2025-04-25T18:20:29Z")

</div>

hey @jessgarson yes but I need as an alert!  
I think it's only just exploratory analysis tool

---

<div class="post-metadata">

**Author:** ![jessgarson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jessgarson/32/129841_2.png) [@jessgarson](https://discuss.elastic.co/u/jessgarson)\
**Post date:** [April 25, 2025, 6:57pm UTC](https://discuss.elastic.co/t/log-rate-spikes-alert/377394/4 "2025-04-25T18:57:25Z")

</div>

Thanks, @erikg, I think I was thinking of combining it the log rate analysis chart discussed here:

> **[Triage threshold breaches | Elastic Docs](https://www.elastic.co/docs/solutions/observability/incident-management/triage-threshold-breaches)**
>
> Threshold breaches occur when an Observability data type reaches or exceeds the threshold set in your custom threshold rule. For example, you might have...

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 25, 2025, 7:28pm UTC](https://discuss.elastic.co/t/log-rate-spikes-alert/377394/5 "2025-04-25T19:28:50Z")

</div>

@erikg What version are you using?

Yes ML job is the right approach.

The are OOTB Jobs or you can create one manually.

The reformatting of the docs makes this a little he hard to find right now.

Go To Observability -\> Logs -\> Anomalies

Click Create or Manage Machine Learnin g

 ![Screenshot 2025-04-25 at 12.13.05 PM](https://us1.discourse-cdn.com/elastic/original/3X/c/3/c3ccfa6a38d6d11792a1bd00adc764dfbe162028.png)

 ![Screenshot 2025-04-25 at 12.13.22 PM](https://us1.discourse-cdn.com/elastic/original/3X/9/e/9ecbd82f964ba8b71f799ca8b67d47f9cbde26c3.png)

I would start with that...

I would be carefull with the start time... it will go back and look at a lot of historical data which can take a long time.

I would not create alerts day one ...

Let it run for a while and look at the results... because it will need to learn...

Then you can create and alert... rule ... got the Job and Right Click...  
Then you Select the Type / Threshold ML Score etcc...

 ![Screenshot 2025-04-25 at 12.25.44 PM](https://us1.discourse-cdn.com/elastic/original/3X/2/e/2e03e6a5af790b0030f29a15d95acd73bd0b21be.png)

 ![Screenshot 2025-04-25 at 12.28.17 PM](https://us1.discourse-cdn.com/elastic/original/3X/2/4/24a3ad8e981dc37b5b170484f821f578ad7dba7e.png)

In addition this job partitions by event.dataset... but maybe you want something different...

See This for OOTB Jobs

> **[Supplied configurations | Elastic Docs](https://www.elastic.co/docs/explore-analyze/machine-learning/anomaly-detection/ootb-ml-jobs)**
>
> Anomaly detection jobs contain the configuration information and metadata necessary to perform an analytics task. Kibana can recognize certain types of...

Then you should experiment by creating an ML job manually with the Wizard it is pretty easy... ish 🙂

I suggest you formulate your job as a uze case and then you can usually translates into an ML Job

> **[Supplied configurations | Elastic Docs](https://www.elastic.co/docs/explore-analyze/machine-learning/anomaly-detection/ootb-ml-jobs)**
>
> Anomaly detection jobs contain the configuration information and metadata necessary to perform an analytics task. Kibana can recognize certain types of...

---

<div class="post-metadata">

**Author:** ![erikg](https://avatars.discourse-cdn.com/v4/letter/e/91b2a8/32.png) [@erikg](https://discuss.elastic.co/u/erikg)\
**Post date:** [April 25, 2025, 7:59pm UTC](https://discuss.elastic.co/t/log-rate-spikes-alert/377394/6 "2025-04-25T19:59:16Z")

</div>

this is it! thanks @stephenb
