# ML Unsupervised question

**URL:** <https://discuss.elastic.co/t/ml-unsupervised-question/322437>\
**Category:** SIEM\
**Created:** [January 4, 2023, 9:02am UTC](https://discuss.elastic.co/t/ml-unsupervised-question/322437 "2023-01-04T09:02:31Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![alex\_su](https://avatars.discourse-cdn.com/v4/letter/a/d6d6ee/32.png) [@alex\_su](https://discuss.elastic.co/u/alex_su)\
**Post date:** [January 4, 2023, 9:02am UTC](https://discuss.elastic.co/t/ml-unsupervised-question/322437/1 "2023-01-04T09:02:31Z")

</div>

Hi, as i know es provide ml to detect unusual event, like "Unusual Windows Username" and another exapmle is " Unusual Hour for a User to Logon".

I have question about unusual meaning as belows.

1. how to build this ml ? like one host one model? or if i have 100 host event log data, we only need one model can handle it?

---

<div class="post-metadata">

**Author:** ![Sergi\_Massaneda\_Dona](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sergi_massaneda_dona/32/107149_2.png) [@Sergi\_Massaneda\_Dona](https://discuss.elastic.co/u/Sergi_Massaneda_Dona)\
**Post date:** [January 4, 2023, 3:28pm UTC](https://discuss.elastic.co/t/ml-unsupervised-question/322437/2 "2023-01-04T15:28:25Z")

</div>

Hello. It is hard to tell based on the question. but we have a couple of blogs that explain the "rare" function in machine learning:

> **[Using Elastic machine learning rare analysis to hunt for the unusual](https://www.elastic.co/blog/using-elastic-machine-learning-rare-analysis-to-hunt-for-the-unusual)**
>
> Learn how Elastic machine learning can be used to easily build a model of your data and apply anomaly detection algorithms to detect what is rare/unusual in the data.

> **[Detecting rare and unusual processes with OOTB machine learning](https://www.elastic.co/blog/detecting-rare-unusual-processes-with-elastic-machine-learning)**
>
> To secure your environment, Elastic Security has many out-of-the-box machine learning configurations for detecting rare activity, networks, and processes, as well as tools to customize your own anomaly detection jobs.

Hope this helps

---

<div class="post-metadata">

**Author:** ![shuchang](https://avatars.discourse-cdn.com/v4/letter/s/f475e1/32.png) [@shuchang](https://discuss.elastic.co/u/shuchang)\
**Post date:** [January 9, 2023, 4:40pm UTC](https://discuss.elastic.co/t/ml-unsupervised-question/322437/3 "2023-01-09T16:40:45Z")

</div>

We have some pre-built jobs that look for rarities in username over a single host:

Auth rare hour for user: [Prebuilt job reference | Elastic Security Solution [8.5] | Elastic](https://www.elastic.co/guide/en/security/current/prebuilt-ml-jobs.html)

Unusual Windows username: [Unusual Windows Username | Elastic Security Solution [8.5] | Elastic](https://www.elastic.co/guide/en/security/current/unusual-windows-username.html)

However it might depend on your situation specifically about your 100 host event log data.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 6, 2023, 4:41pm UTC](https://discuss.elastic.co/t/ml-unsupervised-question/322437/4 "2023-02-06T16:41:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
