# Meachine learning anomaly detection error: no node found

**URL:** <https://discuss.elastic.co/t/meachine-learning-anomaly-detection-error-no-node-found/252525>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-machine-learning\
**Created:** [October 19, 2020, 10:07am UTC](https://discuss.elastic.co/t/meachine-learning-anomaly-detection-error-no-node-found/252525 "2020-10-19T10:07:57Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![TheHunter1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thehunter1/32/80190_2.png) [@TheHunter1](https://discuss.elastic.co/u/TheHunter1)\
**Post date:** [October 19, 2020, 10:07am UTC](https://discuss.elastic.co/t/meachine-learning-anomaly-detection-error-no-node-found/252525/1 "2020-10-19T10:07:57Z")

</div>

Hello,

I am trying elastic machine learning, I tried to run default job for audibeat and I am getting this error in kibana logs :

```auto
server log [11:59:16.059] [error][data][elasticsearch] [status_exception]: No node found to start datafeed [datafeed-linux_network_connection_discovery], allocation explanation [cannot start datafeed [datafeed-linux_network_connection_discovery], because the job's [linux_network_connection_discovery] state is [failed] while state [opened] is required]

```

and this error in Elasticsearch logs

```auto
[2020-10-19T11:59:14,538][INFO][o.e.x.m.j.p.a.AutodetectProcessManager] [VSELK_MASTER] Successfully set job state to [opened] for job [linux_network_configuration_discovery]
[2020-10-19T11:59:14,609][INFO][o.e.x.m.j.p.a.AutodetectProcessManager] [VSELK_MASTER] Successfully set job state to [failed] for job [linux_network_configuration_discovery]
[2020-10-19T11:59:14,702][INFO][o.e.x.m.j.p.a.AutodetectProcessManager] [VSELK_MASTER] Opening job [linux_network_connection_discovery]
[2020-10-19T11:59:14,705][INFO][o.e.x.m.j.p.a.AutodetectProcessManager] [VSELK_MASTER] [linux_network_connection_discovery] Loading model snapshot [N/A], job latest_record_timestamp [N/A]
[2020-10-19T11:59:15,922][INFO][o.e.x.m.p.AbstractNativeProcess] [VSELK_MASTER] [linux_network_connection_discovery] State output finished
[2020-10-19T11:59:15,922][INFO][o.e.x.m.p.l.CppLogMessageHandler] [VSELK_MASTER] [linux_network_connection_discovery] [autodetect/22168] [CResourceMonitor.cc@74] Setting model memory limit to 10 MB
[2020-10-19T11:59:15,922][ERROR][o.e.x.m.p.l.CppLogMessageHandler] [VSELK_MASTER] [linux_network_connection_discovery] [autodetect/22168] [CFieldConfig.cc@184] Cannot specify both a fieldname clause and a field config file
[2020-10-19T11:59:15,922][FATAL][o.e.x.m.p.l.CppLogMessageHandler] [VSELK_MASTER] [linux_network_connection_discovery] [autodetect/22168] [Main.cc@175] Field config could not be interpreted
[2020-10-19T11:59:15,923][ERROR][o.e.x.m.p.AbstractNativeProcess] [VSELK_MASTER] [linux_network_connection_discovery] autodetect process stopped unexpectedly: Cannot specify both a fieldname clause and a field config file
Field config could not be interpreted

```

Could someone help please !

Thanks 🙂

---

<div class="post-metadata">

**Author:** ![droberts195](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/droberts195/32/17692_2.png) [@droberts195](https://discuss.elastic.co/u/droberts195)\
**Post date:** [October 19, 2020, 12:45pm UTC](https://discuss.elastic.co/t/meachine-learning-anomaly-detection-error-no-node-found/252525/2 "2020-10-19T12:45:59Z")

</div>

`Cannot specify both a fieldname clause and a field config file` strongly suggests that the ML native processes are from a different version than the Elasticsearch server that's trying to run them and as a result the arguments provided to and expected by the `autodetect` process are not matching up correctly.

Please can you double check the exact versions of Elasticsearch and the ML `autodetect` process on the node that the log you pasted came from:

```auto
$ESHOME/bin/elasticsearch --version
$ESHOME/modules/x-pack-ml/platform/linux-x86_64/bin/autodetect --version

```

---

<div class="post-metadata">

**Author:** ![TheHunter1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thehunter1/32/80190_2.png) [@TheHunter1](https://discuss.elastic.co/u/TheHunter1)\
**Post date:** [October 19, 2020, 12:53pm UTC](https://discuss.elastic.co/t/meachine-learning-anomaly-detection-error-no-node-found/252525/3 "2020-10-19T12:53:12Z")

</div>

I am using Elasticsearch from code source, so I am trying the version 8.0.0

when I run bin/elasticsearch -- version I get:

```auto
Version: 8.0.0

```

and when I run

```auto
bin/autodetect --version

```

I get:

```auto
Model State Version 34
Quantile State Version 3
autodetect (64 bit): Version based on 8.0.0

```

---

<div class="post-metadata">

**Author:** ![droberts195](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/droberts195/32/17692_2.png) [@droberts195](https://discuss.elastic.co/u/droberts195)\
**Post date:** [October 19, 2020, 1:25pm UTC](https://discuss.elastic.co/t/meachine-learning-anomaly-detection-error-no-node-found/252525/4 "2020-10-19T13:25:51Z")

</div>

Oh, you are building from source on the master branch (at least that's what `Version based on 8.0.0` implies).

We recently did a change that affected the arguments sent from Java to C++: [https://github.com/elastic/elasticsearch/pull/63865](https://github.com/elastic/elasticsearch/pull/63865)

You will need to incorporate the corresponding C++ changes, [https://github.com/elastic/ml-cpp/pull/1540](https://github.com/elastic/ml-cpp/pull/1540), into your local build of the C++. Depending on what you changed this might be as simple as a `git pull` in your `ml-cpp` clone.

---

<div class="post-metadata">

**Author:** ![TheHunter1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thehunter1/32/80190_2.png) [@TheHunter1](https://discuss.elastic.co/u/TheHunter1)\
**Post date:** [October 19, 2020, 1:32pm UTC](https://discuss.elastic.co/t/meachine-learning-anomaly-detection-error-no-node-found/252525/5 "2020-10-19T13:32:30Z")

</div>

Thanks for you answers @droberts195, I will try that and keep you informed of the results

---

<div class="post-metadata">

**Author:** ![TheHunter1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thehunter1/32/80190_2.png) [@TheHunter1](https://discuss.elastic.co/u/TheHunter1)\
**Post date:** [October 22, 2020, 2:57pm UTC](https://discuss.elastic.co/t/meachine-learning-anomaly-detection-error-no-node-found/252525/6 "2020-10-22T14:57:10Z")

</div>

Hello,

I tried to make `git pull` in both `elasticsearch` and `ml-cpp` and it worked perfectly as I am not getting that errors anymore.  
But when I try to create some test jobs ( prebuilt rules ), I got a message on kibana screen "No overall data found" as it's shown in the picture bellow

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/9/4923dbe784aebe30d719b69dcd695107796ae249.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/f/3f1d9b236f656e1fd641b698c8911c858fdcd2a3.png)

Is that mean that I don't have enough data (as I have just 4 hours or data in my index), or it just means that no anomaly has been detected in my data.

Thanks

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [October 22, 2020, 3:14pm UTC](https://discuss.elastic.co/t/meachine-learning-anomaly-detection-error-no-node-found/252525/7 "2020-10-22T15:14:58Z")

</div>

> [@TheHunter1](#):
>
> Is that mean that I don't have enough data (as I have just 4 hours or data in my index), or it just means that no anomaly has been detected in my data.

Both!

You certainly need to allow a lot more data (ideally many days) to be seen by ML. Even so, it is possible that even after a while, there might not be anything remarkably unusual occurring in the data. If you want to test how ML works, the ideal situation is to have several days or even weeks worth of historical data to learn on, and then contrive the situation that you'd like to see get detected.

---

<div class="post-metadata">

**Author:** ![TheHunter1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thehunter1/32/80190_2.png) [@TheHunter1](https://discuss.elastic.co/u/TheHunter1)\
**Post date:** [October 22, 2020, 3:19pm UTC](https://discuss.elastic.co/t/meachine-learning-anomaly-detection-error-no-node-found/252525/8 "2020-10-22T15:19:32Z")

</div>

Thanks for your answer @richcollier, I will let at least 1month of data in my index to test it again.  
Best regards

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 19, 2020, 3:20pm UTC](https://discuss.elastic.co/t/meachine-learning-anomaly-detection-error-no-node-found/252525/9 "2020-11-19T15:20:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
