# Machine learning use case - Anomaly Detection

**URL:** <https://discuss.elastic.co/t/machine-learning-use-case-anomaly-detection/379237>\
**Category:** SIEM\
**Created:** [June 17, 2025, 10:26am UTC](https://discuss.elastic.co/t/machine-learning-use-case-anomaly-detection/379237 "2025-06-17T10:26:28Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![sunith](https://avatars.discourse-cdn.com/v4/letter/s/f4b2a3/32.png) [@sunith](https://discuss.elastic.co/u/sunith)\
**Post date:** [June 17, 2025, 10:26am UTC](https://discuss.elastic.co/t/machine-learning-use-case-anomaly-detection/379237/1 "2025-06-17T10:26:28Z")

</div>

Hi Everyone,

I'm currently developing and testing a Machine Learning-based use case in Elastic for anomaly detection. I've cloned and configured the ML job "auth\_rare\_hour\_for\_a\_user", which is designed to detect user logins at unusual hours. The job is active and appears to be functioning correctly, with all relevant log sources added to the data feed.

In Kibana, I’ve also configured a "Security Alert rule" using this ML job. The rule is set up as follows:

Rule Name: "auth\_rare\_hour\_for\_a\_user"  
Description: Detects user logins at times that are unusual for the user, which may indicate credentialed access via a compromised account or unauthorized activity during non-business hours.

To test the setup, I performed several login activities during off-hours that should be considered anomalous. However, no alerts have been triggered so far.

Could anyone advise if I might be missing a step or configuration detail for ML-based detection rules like this? Are there specific thresholds, lookback periods, or job configurations I should double-check?

Any insights or suggestions would be greatly appreciated.

Thanks in advance!

---

<div class="post-metadata">

**Author:** ![jessgarson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jessgarson/32/129841_2.png) [@jessgarson](https://discuss.elastic.co/u/jessgarson)\
**Post date:** [June 24, 2025, 8:13pm UTC](https://discuss.elastic.co/t/machine-learning-use-case-anomaly-detection/379237/2 "2025-06-24T20:13:33Z")

</div>

Thanks for reaching out, @sunith. I have a few follow-up questions here:

- What version of Elastic are you using?
- Could you provide more information about how this alert is configured? Attaching a picture of the configuration could also be helpful.

Best,

Jessica

---

<div class="post-metadata">

**Author:** ![sunith](https://avatars.discourse-cdn.com/v4/letter/s/f4b2a3/32.png) [@sunith](https://discuss.elastic.co/u/sunith)\
**Post date:** [July 2, 2025, 12:54pm UTC](https://discuss.elastic.co/t/machine-learning-use-case-anomaly-detection/379237/3 "2025-07-02T12:54:42Z")

</div>

Thanks for the reply @jessgarson

Elastic version 8.18.3

Screenshot of the ML rule and associated job

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/5/e5987ad379221e4a2d4c3925d4f79ce05a5e576b.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/0/d05d3af63821b63d93b8329c5090c2c3b3c9c884.png)

---

<div class="post-metadata">

**Author:** ![jessgarson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jessgarson/32/129841_2.png) [@jessgarson](https://discuss.elastic.co/u/jessgarson)\
**Post date:** [July 2, 2025, 10:10pm UTC](https://discuss.elastic.co/t/machine-learning-use-case-anomaly-detection/379237/4 "2025-07-02T22:10:46Z")

</div>

Thanks for following up, @sunith. One thing that has tripped me up with anomaly detection in the past is that it requires a sufficient amount of baseline data (typically 2-4 weeks) to establish standard patterns before detecting anomalies reliably. Could this be what's happening here?

---

<div class="post-metadata">

**Author:** ![sunith](https://avatars.discourse-cdn.com/v4/letter/s/f4b2a3/32.png) [@sunith](https://discuss.elastic.co/u/sunith)\
**Post date:** [July 4, 2025, 10:35am UTC](https://discuss.elastic.co/t/machine-learning-use-case-anomaly-detection/379237/5 "2025-07-04T10:35:14Z")

</div>

Thanks for the reply. Yes, for baseline data I gave 1 month of data to this job.

---

<div class="post-metadata">

**Author:** ![jessgarson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jessgarson/32/129841_2.png) [@jessgarson](https://discuss.elastic.co/u/jessgarson)\
**Post date:** [July 7, 2025, 5:46pm UTC](https://discuss.elastic.co/t/machine-learning-use-case-anomaly-detection/379237/6 "2025-07-07T17:46:23Z")

</div>

Thanks for following up, @sunith. As a next step, please verify that the bucket span is appropriate for your use case (typically 15 minutes to 1 hour for login patterns).

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [July 10, 2025, 11:56am UTC](https://discuss.elastic.co/t/machine-learning-use-case-anomaly-detection/379237/7 "2025-07-10T11:56:54Z")

</div>

> [@sunith](#):
>
> Yes, for baseline data I gave 1 month of data to this job.

It is also important that the baseline includes many examples of "normal" login times for the particular user you are testing. You should have dozens or even hundreds of "normal" examples of logins for that user before you attempt to inject an "anomalous" one.

If there aren't many (or worst case, ANY) examples of "normal" login times for that user your are testing, then the login events you inject in testing won't have enough to contrast against to determine unusualness.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 7, 2025, 11:57am UTC](https://discuss.elastic.co/t/machine-learning-use-case-anomaly-detection/379237/8 "2025-08-07T11:57:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
