# Showing 'actual' & 'typical' values in ML anomaly detection alert

**URL:** <https://discuss.elastic.co/t/showing-actual-typical-values-in-ml-anomaly-detection-alert/322810>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-machine-learning\
**Created:** [January 10, 2023, 9:19am UTC](https://discuss.elastic.co/t/showing-actual-typical-values-in-ml-anomaly-detection-alert/322810 "2023-01-10T09:19:58Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![nospace](https://avatars.discourse-cdn.com/v4/letter/n/e47c2d/32.png) [@nospace](https://discuss.elastic.co/u/nospace)\
**Post date:** [January 10, 2023, 9:19am UTC](https://discuss.elastic.co/t/showing-actual-typical-values-in-ml-anomaly-detection-alert/322810/1 "2023-01-10T09:19:58Z")

</div>

Hey folks,

We're running a couple of ML jobs for anomaly detection with mail alerts. For faster detection of false alerts I would like to extend the alert with the values from 'actual' and 'typical'.

The [documentation](https://www.elastic.co/guide/en/machine-learning/current/ml-configuring-alerts.html#action-variables) specifies that the values are available, but shows no details on the syntax to add them.

We're currently using the default alert template:

```auto
Elastic Stack Machine Learning Alert:
- Job IDs: {{context.jobIds}}
- Time: {{context.timestampIso8601}}
- Anomaly score: {{context.score}}

{{context.message}}

{{#context.topInfluencers.length}}
  Top influencers:
  {{#context.topInfluencers}}
    {{influencer_field_name}} = {{influencer_field_value}} [{{score}}]
  {{/context.topInfluencers}}
{{/context.topInfluencers.length}}

{{#context.topRecords.length}}
  Top records:
  {{#context.topRecords}}
    {{function}}({{field_name}}) {{by_field_value}} {{over_field_value}} {{partition_field_value}} [{{score}}]
  {{/context.topRecords}}
{{/context.topRecords.length}}

{{! Replace kibanaBaseUrl if not configured in Kibana }}
[Open in Anomaly Explorer]({{{kibanaBaseUrl}}}{{{context.anomalyExplorerUrl}}})

```

I tried several variations but the fields came always back empty:

```auto
{{#context.topRecords.length}}
  Top records:
  {{#context.topRecords}}
    {{function}}({{field_name}}) {{by_field_value}} {{over_field_value}} {{partition_field_value}} [{{score}}]
    {{function}}({{field_name}}) {{by_field_value}} {{over_field_value}} {{partition_field_value}} [{{typical}}]
    {{function}}({{field_name}}) {{by_field_value}} {{over_field_value}} {{partition_field_value}} [{{actual}}]
  {{/context.topRecords}}
{{/context.topRecords.length}}

```

-\> Top records: count() [86] count() count()

```auto
{{#context.topRecords.length}}
  Top records:
  {{#context.topRecords}}
    {{function}}({{field_name}}) {{by_field_value}} {{over_field_value}} {{partition_field_value}} [{{score}}] Actual: [{{actual}}] Typical: [{{typical}}]
  {{/context.topRecords}}
{{/context.topRecords.length}}

```

-\> Top records: count() [99] Actual: Typical:

Could you kindly help me in which direction to look?

---

<div class="post-metadata">

**Author:** ![darnautov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/darnautov/32/70608_2.png) [@darnautov](https://discuss.elastic.co/u/darnautov)\
**Post date:** [January 25, 2023, 9:47am UTC](https://discuss.elastic.co/t/showing-actual-typical-values-in-ml-anomaly-detection-alert/322810/2 "2023-01-25T09:47:33Z")

</div>

Hi @nospace,

What is the Kibana version you're using? Actual and Typical values [were added](https://github.com/elastic/kibana/pull/118006) to the alerting context in `8.1`. The default alert template has been updated accordingly.

Hope it helps.

---

<div class="post-metadata">

**Author:** ![nospace](https://avatars.discourse-cdn.com/v4/letter/n/e47c2d/32.png) [@nospace](https://discuss.elastic.co/u/nospace)\
**Post date:** [January 25, 2023, 9:56am UTC](https://discuss.elastic.co/t/showing-actual-typical-values-in-ml-anomaly-detection-alert/322810/3 "2023-01-25T09:56:58Z")

</div>

Hey @darnautov,

Thx for having a look, this helped indeed.

Our cluster still runs an earlier supported version and I didn't realise that the feature was added later. Guess I gonna poke the infrastructure team for an update 😉

Thanks again 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 22, 2023, 9:57am UTC](https://discuss.elastic.co/t/showing-actual-typical-values-in-ml-anomaly-detection-alert/322810/4 "2023-02-22T09:57:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
