# Machine Learning 1 Day Bucket Span and Alerts

**URL:** <https://discuss.elastic.co/t/machine-learning-1-day-bucket-span-and-alerts/317825>\
**Category:** Kibana\
**Tags:** elastic-stack-machine-learning\
**Created:** [October 31, 2022, 1:45pm UTC](https://discuss.elastic.co/t/machine-learning-1-day-bucket-span-and-alerts/317825 "2022-10-31T13:45:23Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![edang](https://avatars.discourse-cdn.com/v4/letter/e/a183cd/32.png) [@edang](https://discuss.elastic.co/u/edang)\
**Post date:** [October 31, 2022, 1:45pm UTC](https://discuss.elastic.co/t/machine-learning-1-day-bucket-span-and-alerts/317825/1 "2022-10-31T13:45:23Z")

</div>

Hi All,

I have unique data coming in once a day for a field and set up an advanced ML job with a bucket span of one day accordingly. The configured detector is a summation of a unique number field partitioned by another field.

Alerts are also set up so any anomalies above a threshold is emailed to me but I would also like to know when data comes in late (compared to its historic timing).

How could I configure my ML to satisfy my needs?

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [November 1, 2022, 1:45pm UTC](https://discuss.elastic.co/t/machine-learning-1-day-bucket-span-and-alerts/317825/2 "2022-11-01T13:45:39Z")

</div>

Sounds like a second ML job is required using `time_of_day` function: [Appendix P: Time functions | Machine Learning in the Elastic Stack [8.4] | Elastic](https://www.elastic.co/guide/en/machine-learning/current/ml-time-functions.html)

---

<div class="post-metadata">

**Author:** ![edang](https://avatars.discourse-cdn.com/v4/letter/e/a183cd/32.png) [@edang](https://discuss.elastic.co/u/edang)\
**Post date:** [November 2, 2022, 1:54pm UTC](https://discuss.elastic.co/t/machine-learning-1-day-bucket-span-and-alerts/317825/3 "2022-11-02T13:54:45Z")

</div>

Okay, thank you. That is very helpful.

A follow up question I have about this is, would 1 ML job with multiple detectors be more efficient?

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [November 3, 2022, 5:52pm UTC](https://discuss.elastic.co/t/machine-learning-1-day-bucket-span-and-alerts/317825/4 "2022-11-03T17:52:00Z")

</div>

In general, yes. Because in each bucket\_span, the data only needs to be queried once, then applied to both detectors. However, the viewing/interpreting of the results is easier in our UI (I find) if a job only has one detector.

---

<div class="post-metadata">

**Author:** ![edang](https://avatars.discourse-cdn.com/v4/letter/e/a183cd/32.png) [@edang](https://discuss.elastic.co/u/edang)\
**Post date:** [November 9, 2022, 4:28pm UTC](https://discuss.elastic.co/t/machine-learning-1-day-bucket-span-and-alerts/317825/5 "2022-11-09T16:28:51Z")

</div>

Hi richcollier, I have set up the ML according to the time\_of\_day function with a bucket span of 1 day. However, it is not exactly how I would prefer it to behave.

In your experience, is it possible to get real time alerts for late data with unique data coming in once a day?

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [November 9, 2022, 7:46pm UTC](https://discuss.elastic.co/t/machine-learning-1-day-bucket-span-and-alerts/317825/6 "2022-11-09T19:46:27Z")

</div>

Note in : [Appendix P: Time functions | Machine Learning in the Elastic Stack [8.11] | Elastic](https://www.elastic.co/guide/en/machine-learning/current/ml-time-functions.html)

> - Shorter bucket spans (for example, 10 minutes) are recommended when performing a `time_of_day` or `time_of_week` analysis. The time of the events being modeled are not affected by the bucket span, but a shorter bucket span enables quicker alerting on unusual events.

---

<div class="post-metadata">

**Author:** ![edang](https://avatars.discourse-cdn.com/v4/letter/e/a183cd/32.png) [@edang](https://discuss.elastic.co/u/edang)\
**Post date:** [November 10, 2022, 2:23pm UTC](https://discuss.elastic.co/t/machine-learning-1-day-bucket-span-and-alerts/317825/7 "2022-11-10T14:23:21Z")

</div>

The separate ML with the time of day detector worked well for late data congestion!

My current configuration for the first ML is a summation of a number field by a field that is consumed once per day. Therefore, I set a bucket span of 1 day. However, when setting up my alerts, I will only get 1 alert at the end of day (after the ML has run).

Are there any configurations for the ML to run real time for the alerts to be real time as well (with the constraint of how my data is coming in)?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 8, 2022, 2:23pm UTC](https://discuss.elastic.co/t/machine-learning-1-day-bucket-span-and-alerts/317825/8 "2022-12-08T14:23:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
