# Machine Learning job for counters who need delta's

**URL:** <https://discuss.elastic.co/t/machine-learning-job-for-counters-who-need-deltas/184762>\
**Category:** Kibana\
**Tags:** elastic-stack-machine-learning\
**Created:** [June 7, 2019, 1:36pm UTC](https://discuss.elastic.co/t/machine-learning-job-for-counters-who-need-deltas/184762 "2019-06-07T13:36:46Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [June 7, 2019, 1:36pm UTC](https://discuss.elastic.co/t/machine-learning-job-for-counters-who-need-deltas/184762/1 "2019-06-07T13:36:47Z")

</div>

Hello,

We have some data like sflows which has fields:

- output\_octets
- input\_octets  
the values of the above fields is an incrementing counter.

Is there a way to make an Elastic machine learning job which can detect drops in traffic somehow? To do that it would have to detect changes in the rate the octets increment. I've tried, but was unable to do that.

Grtz

Willem

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [June 7, 2019, 3:32pm UTC](https://discuss.elastic.co/t/machine-learning-job-for-counters-who-need-deltas/184762/2 "2019-06-07T15:32:12Z")

</div>

Not sure what you tried, but this should work fine as is. I just did a quick mockup using the following CSV, with a contrived discontinuity of slope in it:

> <https://gist.github.com/richcollier/a42bc40c31bec8216391e76c79e5d491>

Imported into elasticsearch with [File Upload](https://www.elastic.co/blog/importing-csv-and-log-data-into-elasticsearch-with-file-data-visualizer). Configured an ML job:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/1/61df50fa60c7a028eeb98483aef433a647b685ec.jpeg)

It properly found the discontinuity:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/8/68413765dea353afdb564366383561976f59c527.jpeg)

---

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [June 7, 2019, 4:55pm UTC](https://discuss.elastic.co/t/machine-learning-job-for-counters-who-need-deltas/184762/3 "2019-06-07T16:55:22Z")

</div>

@richcollier Can it also show this per host? Do I need to configure the host as influencer?

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [June 7, 2019, 4:57pm UTC](https://discuss.elastic.co/t/machine-learning-job-for-counters-who-need-deltas/184762/4 "2019-06-07T16:57:16Z")

</div>

Yes, you could do it per host - just use the Multi-metric job wizard and split on `host`

---

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [June 7, 2019, 6:27pm UTC](https://discuss.elastic.co/t/machine-learning-job-for-counters-who-need-deltas/184762/5 "2019-06-07T18:27:13Z")

</div>

@richcollier Thanks, I think I got it:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/4/141ac4d668a4c4b774a1c77789a96eef3bfbdb2c.png)

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [June 7, 2019, 6:30pm UTC](https://discuss.elastic.co/t/machine-learning-job-for-counters-who-need-deltas/184762/6 "2019-06-07T18:30:19Z")

</div>

Cool - but it would be more effective to split the analysis on `host` using the Multi-metric job wizard rather than merely relying on using the `host` as an influencer.

---

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [June 7, 2019, 10:07pm UTC](https://discuss.elastic.co/t/machine-learning-job-for-counters-who-need-deltas/184762/7 "2019-06-07T22:07:59Z")

</div>

Got it, used switchinterface alias as split field looks promising. Curious at the results in a few weeks. Tx for the help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2019, 10:08pm UTC](https://discuss.elastic.co/t/machine-learning-job-for-counters-who-need-deltas/184762/8 "2019-07-05T22:08:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
