I am trying out DNS_data_exfiltration which is a part of machine learning recipes in elasticsearch .Below is my job configuration and i am running packetbeat in my machine.
Just click on "single metric viewer" it will automaticaly open the job you have choosen at anomaly explorer, you also can click on an anomaly then click on the ... icon and select "view series" it will lead you to the Single Metric Viewer.
You also seem to have some warning on the job.
If you have tried what I said before, does it shows any error?
Not all jobs (or more accurately, not all "detectors" within jobs) are able to be plotted with the Single Metric View. One such detector is when the info_content functions are used. The Single Metric View only works for mean , min , max , sum , count , distinct_count , median , or rare and if the detector did not use a script_field that was defined in the datafeed configuration.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.