# Machine Learning - Categorization status changed to warn

**URL:** <https://discuss.elastic.co/t/machine-learning-categorization-status-changed-to-warn/257841>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-machine-learning\
**Created:** [December 7, 2020, 11:59am UTC](https://discuss.elastic.co/t/machine-learning-categorization-status-changed-to-warn/257841 "2020-12-07T11:59:16Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![OmarDacca](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/omardacca/32/68171_2.png) [@OmarDacca](https://discuss.elastic.co/u/OmarDacca)\
**Post date:** [December 7, 2020, 11:59am UTC](https://discuss.elastic.co/t/machine-learning-categorization-status-changed-to-warn/257841/1 "2020-12-07T11:59:17Z")

</div>

Hi,

I created a categorization ml job, and I get this message a lot:  
Categorization status changed to 'warn' for 'client\_event\_key' '\*\*\*\*' after 1186 buckets

I quote the following from the documentation

> **[Detecting anomalous categories of data | Machine Learning in the Elastic...](https://www.elastic.co/guide/en/machine-learning/7.10/ml-configuring-categories.html)**

> If the categorization status for a partition changes to `warn` , it doesn’t categorize well and can cause a lot of unnecessary resource usage.

why it doesn’t categorize well ? and what should I do ?

Thanks

---

<div class="post-metadata">

**Author:** ![BenTrent](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bentrent/32/33915_2.png) [@BenTrent](https://discuss.elastic.co/u/BenTrent)\
**Post date:** [December 7, 2020, 12:20pm UTC](https://discuss.elastic.co/t/machine-learning-categorization-status-changed-to-warn/257841/2 "2020-12-07T12:20:27Z")

</div>

Categorization only works well on machine generated text where certain entries contain constant terms around which to cluster.

`client_event_key` not knowing how the values look, I can only assume that this text field contains mostly random values.

It is possible that the field SHOULD categorize well, but should first be passed through a custom analyzer. [https://www.elastic.co/guide/en/machine-learning/7.9/ml-configuring-categories.html#ml-configuring-analyzer](https://www.elastic.co/guide/en/machine-learning/7.9/ml-configuring-categories.html#ml-configuring-analyzer)

---

<div class="post-metadata">

**Author:** ![droberts195](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/droberts195/32/17692_2.png) [@droberts195](https://discuss.elastic.co/u/droberts195)\
**Post date:** [December 8, 2020, 10:27am UTC](https://discuss.elastic.co/t/machine-learning-categorization-status-changed-to-warn/257841/3 "2020-12-08T10:27:13Z")

</div>

Another thing you can do is look at the model size stats for the job, which are on the "Counts" tab if you expand the row for the job in the jobs list.

This will include stats like how many documents got categorized and how many categories there were. It might make it clearer why the status changed to `warn`. For example, if 10000 messages were categorized and created 9000 different categories then categorization would be pretty useless on that data set. Similarly if there was only 1 category detected.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 5, 2021, 10:27am UTC](https://discuss.elastic.co/t/machine-learning-categorization-status-changed-to-warn/257841/4 "2021-01-05T10:27:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
