# Machine Learning

**URL:** <https://discuss.elastic.co/t/machine-learning/285987>\
**Category:** SIEM\
**Tags:** elastic-stack-machine-learning\
**Created:** [October 6, 2021, 7:33am UTC](https://discuss.elastic.co/t/machine-learning/285987 "2021-10-06T07:33:56Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![alaine](https://avatars.discourse-cdn.com/v4/letter/a/22d042/32.png) [@alaine](https://discuss.elastic.co/u/alaine)\
**Post date:** [October 6, 2021, 7:33am UTC](https://discuss.elastic.co/t/machine-learning/285987/1 "2021-10-06T07:33:56Z")

</div>

Good Morning,

Ran into a weird use case and wondering if anyone has suggestions. We have a couple thousand endpoints sending winlogbeats to our cluster, and we are trying to provide some kind of visibility into uptime or percentage of hosts reporting in. I am wondering if this is something we can set up in machine learning.

Wondering if you guys have any thoughts or suggestions on the matter.

Thanks,  
Alex

---

<div class="post-metadata">

**Author:** ![sholzhauer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sholzhauer/32/110282_2.png) [@sholzhauer](https://discuss.elastic.co/u/sholzhauer)\
**Post date:** [October 7, 2021, 11:08am UTC](https://discuss.elastic.co/t/machine-learning/285987/2 "2021-10-07T11:08:02Z")

</div>

Using ML you could create a job which looks at time of day or time of week anomalies split over the hosts. This way if a hosts is active on a anomalous time you will know.  
A second detector could be count of events split on hosts as well as the same but to the population.

Another option you have is to switch to fleet, which will show you what agents are online/offline.

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [October 7, 2021, 1:13pm UTC](https://discuss.elastic.co/t/machine-learning/285987/3 "2021-10-07T13:13:21Z")

</div>

sure an ML job that queries the metricbeat index and does a `low_count` partitioned (split) on hostname should do the trick. If the volume of documents ingested by any beat suddenly drops, it will be flagged as anomalous and you can optionally alert upon that.

But, I will say that you probably can build a Watch (similar to what's [discussed here](https://discuss.elastic.co/t/create-alerts-in-packetbeat-monitoring/167970)) to accomplish it without the need for ML.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2021, 1:13pm UTC](https://discuss.elastic.co/t/machine-learning/285987/4 "2021-11-04T13:13:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
