# ML anomaly detection alert

**URL:** <https://discuss.elastic.co/t/ml-anomaly-detection-alert/376374>\
**Category:** SIEM\
**Created:** [March 25, 2025, 10:36am UTC](https://discuss.elastic.co/t/ml-anomaly-detection-alert/376374 "2025-03-25T10:36:44Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![sunith](https://avatars.discourse-cdn.com/v4/letter/s/f4b2a3/32.png) [@sunith](https://discuss.elastic.co/u/sunith)\
**Post date:** [March 25, 2025, 10:36am UTC](https://discuss.elastic.co/t/ml-anomaly-detection-alert/376374/1 "2025-03-25T10:36:44Z")

</div>

Hello,

Could anyone please help me with this?

I am working on machine learning-based anomaly detection use cases using Elastic’s built-in anomaly detection job, **"auth\_rare\_hour\_for\_a\_user"**. I integrated this job into a machine learning rule. After a few days of the learning period, the rule triggered an alert for a user.

Based on Elastic’s documentation, the rule’s conditions and alerting criteria are outlined. However, I would like to understand where I can find details on **how** the alert was triggered — specifically, what deviation from the baseline was detected that led to this alert.

Additionally, from a SOC analyst's perspective, it's important to know how the alert was generated and how to effectively triage these types of machine learning-based alerts. Where can this information be found or derived to support the analyst during the investigation?

Thanks in advance 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 22, 2025, 10:36am UTC](https://discuss.elastic.co/t/ml-anomaly-detection-alert/376374/2 "2025-04-22T10:36:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
