# Machine Learning model issue

**URL:** <https://discuss.elastic.co/t/machine-learning-model-issue/362143>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-machine-learning\
**Created:** [June 27, 2024, 9:30am UTC](https://discuss.elastic.co/t/machine-learning-model-issue/362143 "2024-06-27T09:30:17Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Marwan\_Ezz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marwan_ezz/32/123408_2.png) [@Marwan\_Ezz](https://discuss.elastic.co/u/Marwan_Ezz)\
**Post date:** [June 27, 2024, 9:30am UTC](https://discuss.elastic.co/t/machine-learning-model-issue/362143/1 "2024-06-27T09:30:17Z")

</div>

I'm using Elasticsearch machine learning advanced model to detect anomalies in the trend of our failures.

I'm having an issue that the failure count is increasing everyday at the same time so the model have learnt that it is the normal trend however it is not normal and it should be detected as anomaly.

I tried to use the custom rules in the model but I have multiple services which are having variance in the count so I can't use the actual or typical.

What is the work around in this scenario?

---

<div class="post-metadata">

**Author:** ![valeriy42](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/valeriy42/32/82758_2.png) [@valeriy42](https://discuss.elastic.co/u/valeriy42)\
**Post date:** [July 1, 2024, 7:49am UTC](https://discuss.elastic.co/t/machine-learning-model-issue/362143/2 "2024-07-01T07:49:54Z")

</div>

Hello @Marwan_Ezz ,

you need to [revert the model to a snapshot](https://www.elastic.co/guide/en/elasticsearch/reference/current/ml-revert-snapshot.html) before the regular failure count has started in your data.

Then you need to use customer rule e.g. with calendar event and action `skip_model` for the time period when the failure increase happens.

If what you want the model not to learn doesn't happen at a regular time, it's difficult to say how to formulate the rule in general. You need to provide more information and maybe some single metric viewer graphs.

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [July 8, 2024, 8:55pm UTC](https://discuss.elastic.co/t/machine-learning-model-issue/362143/3 "2024-07-08T20:55:35Z")

</div>

> [@Marwan\_Ezz](#):
>
> I'm having an issue that the failure count is increasing everyday at the same time so the model have learnt that it is the normal trend however it is not normal and it should be detected as anomaly.

Not to get too philosophical, but if it changes every day it actually _is_ normal - that's what it does. 🙂
