# ML/Alerting for amount of successful transactions

**URL:** <https://discuss.elastic.co/t/ml-alerting-for-amount-of-successful-transactions/270114>\
**Category:** Elastic Observability\
**Tags:** elastic-stack-machine-learning, elastic-stack-alerting\
**Created:** [April 14, 2021, 1:17pm UTC](https://discuss.elastic.co/t/ml-alerting-for-amount-of-successful-transactions/270114 "2021-04-14T13:17:41Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![mattvl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattvl/32/83862_2.png) [@mattvl](https://discuss.elastic.co/u/mattvl)\
**Post date:** [April 14, 2021, 1:17pm UTC](https://discuss.elastic.co/t/ml-alerting-for-amount-of-successful-transactions/270114/1 "2021-04-14T13:17:41Z")

</div>

Hello,

I would like to create some sort of alert that uses the ML capability to notify me if the successful transaction rate for a specific service is anomalous.

For example:  
Let's assume the trend of successful transactions is 100/day. If one day I get 50 or 150 I get notified and I can check what's going on.

I have read the documentation and I understand I need to use the Anomaly Detection feature, but the pre-configured jobs all point to a specific property to monitor (e.g. service.name). I want to monitor the number of successful transactions for a specific service.

Could you please point me in the right direction for this?

Thanks in advance 🙂

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [April 14, 2021, 2:35pm UTC](https://discuss.elastic.co/t/ml-alerting-for-amount-of-successful-transactions/270114/2 "2021-04-14T14:35:26Z")

</div>

Create a job from the ML UI that points to the index of interest (or leverages a Saved Search of interest) and then uses the `count` detector:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/1/e151e36afe0436019a633ee7eebe9ec89fe9cc76.png)

Optionally, you can "split" the job "for every" categorical field (like `service.name` in your case, but here I will choose `response.keyword`

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/9/696a2d041db5d45e1fc5537742c97727b8714417.png)

The end result is anomalies found in the spike or drop of events per unit time:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/e/0e49121133c7845a214747cbc0b526220c1f5870.png)

---

<div class="post-metadata">

**Author:** ![mattvl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattvl/32/83862_2.png) [@mattvl](https://discuss.elastic.co/u/mattvl)\
**Post date:** [April 16, 2021, 8:32am UTC](https://discuss.elastic.co/t/ml-alerting-for-amount-of-successful-transactions/270114/3 "2021-04-16T08:32:56Z")

</div>

Thanks for your reply @richcollier.  
I managed to create the ML job as you described, how can I turn it into some sort of alert? My end goal is to get notified if the number of successful transactions of the previous day was below average.

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [April 16, 2021, 5:03pm UTC](https://discuss.elastic.co/t/ml-alerting-for-amount-of-successful-transactions/270114/4 "2021-04-16T17:03:40Z")

</div>

If you are using 7.11 or earlier, ML uses Watcher to do the alerting (see old, but still relevant blog here: [Alerting on Machine Learning Jobs in Elasticsearch | Elastic Blog](https://www.elastic.co/blog/alerting-on-machine-learning-jobs-in-elasticsearch-v55))

If you are using 7.12+ ML now uses the new alerting framework in Kibana. See the new docs here: [Configuring anomaly detection alerts | Machine Learning in the Elastic Stack [7.12] | Elastic](https://www.elastic.co/guide/en/machine-learning/7.12/ml-configuring-alerts.html)

---

<div class="post-metadata">

**Author:** ![mattvl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mattvl/32/83862_2.png) [@mattvl](https://discuss.elastic.co/u/mattvl)\
**Post date:** [April 19, 2021, 1:30pm UTC](https://discuss.elastic.co/t/ml-alerting-for-amount-of-successful-transactions/270114/5 "2021-04-19T13:30:42Z")

</div>

Thanks a lot. Is it my understanding correct that if I have a baseline of 100 requests per day, the alert will notify me if one day I get less or more? Or does it work only if I get more?

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [April 19, 2021, 2:02pm UTC](https://discuss.elastic.co/t/ml-alerting-for-amount-of-successful-transactions/270114/6 "2021-04-19T14:02:54Z")

</div>

a detector configuration of the `count` detector function finds anomalies on both the high side and low side (whereas the one-sided detector functions `high_count` and `low_count` only detect anomalies in one direction).

A real astute user might notice that the highest sensitivity possible is two use a job that has two detectors configured (one with `high_count` and one with `low_count`). This configuration has higher fidelity, especially in the case where the dynamic ranges of anomalies on the high side are drastically different than on the low side (i.e. spikes that tend to be much larger in magnitude than the dips). Because each detector maintains its own normalization table, having separate normalized scoring for the two detectors gives more sensitivity control.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 8:28am UTC](https://discuss.elastic.co/t/ml-alerting-for-amount-of-successful-transactions/270114/7 "2022-11-04T08:28:44Z")

</div>


