# Spike Detection in a Time-Series

**URL:** <https://discuss.elastic.co/t/spike-detection-in-a-time-series/2626>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [June 13, 2015, 7:35pm UTC](https://discuss.elastic.co/t/spike-detection-in-a-time-series/2626 "2015-06-13T19:35:37Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sandipan\_Basu](https://avatars.discourse-cdn.com/v4/letter/s/97f17d/32.png) [@Sandipan\_Basu](https://discuss.elastic.co/u/Sandipan_Basu)\
**Post date:** [June 13, 2015, 7:35pm UTC](https://discuss.elastic.co/t/spike-detection-in-a-time-series/2626/1 "2015-06-13T19:35:38Z")

</div>

Hi there,

I am trying to build a watch which alerts on spikes (both up or down) over a time series of a specific field. To illustrate this with an example if my values of a field say cpu is [20,23,24,25,50,52,18,19,20,90] , I want to to be notified when cpu hits 50 for upward spike and again at 18 for downward spike.

I seems to hit a roadblock in defining an appropriate watcher query for this as the normal aggregation functions is not helping. It may so happen that I am ignorant on how to create a proper query DSL on elasticsearch for this.

What could I do to fix this ?

---

<div class="post-metadata">

**Author:** ![Johntdyer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/johntdyer/32/3424_2.png) [@Johntdyer](https://discuss.elastic.co/u/Johntdyer)\
**Post date:** [June 21, 2015, 2:51pm UTC](https://discuss.elastic.co/t/spike-detection-in-a-time-series/2626/2 "2015-06-21T14:51:35Z")

</div>

+1, I am interested in this as well

---

<div class="post-metadata">

**Author:** ![Srinath29](https://avatars.discourse-cdn.com/v4/letter/s/49beb7/32.png) [@Srinath29](https://discuss.elastic.co/u/Srinath29)\
**Post date:** [February 21, 2016, 11:26am UTC](https://discuss.elastic.co/t/spike-detection-in-a-time-series/2626/3 "2016-02-21T11:26:51Z")

</div>

Even I am interested. This is one of general need for alerts. I think watcher should come up with it.

---

<div class="post-metadata">

**Author:** ![skearns](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skearns/32/125945_2.png) [@skearns](https://discuss.elastic.co/u/skearns)\
**Post date:** [February 21, 2016, 4:22pm UTC](https://discuss.elastic.co/t/spike-detection-in-a-time-series/2626/4 "2016-02-21T16:22:17Z")

</div>

Apologies for the long gap in reply here. In Elasticsearch 2.0, we added a new type of aggregations, called pipeline aggregations, which make it easy to do various types of math on the output of existing aggregations.

Zach wrote a great 3-part blog post about how to build a statistical anomaly detector using pipeline aggregations and Watcher, our alerting and automation product.

> **[Implementing a Statistical Anomaly Detector in Elasticsearch - Part 1
	  	 |...](https://www.elastic.co/blog/implementing-a-statistical-anomaly-detector-part-1)**
>
> This graph shows the min/max/avg of 45 million data points (75,000 individual time series over 600 hours). There are eight large-scale, simulated disruptions in this graph...can you spot them? No? It’...

  

> **[Implementing a statistical anomaly detector in Elasticsearch - Part 2](https://www.elastic.co/blog/implementing-a-statistical-anomaly-detector-part-2)**
>
> In part 2 of this series on building a statistical anomaly detector, we graph the output in Timelion, a Kibana app for graphing time-series

  

> **[Implementing a Statistical Anomaly Detector in Elasticsearch - Part 3](https://www.elastic.co/blog/implementing-a-statistical-anomaly-detector-part-3)**
>
> In the final article of this three-part series, we build a fully automated anomaly detector using Watcher to send email alerts.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:46pm UTC](https://discuss.elastic.co/t/spike-detection-in-a-time-series/2626/5 "2017-07-06T13:46:56Z")

</div>



---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [July 19, 2017, 2:54am UTC](https://discuss.elastic.co/t/spike-detection-in-a-time-series/2626/6 "2017-07-19T02:54:26Z")

</div>

Just putting this here for future viewers to see that advanced machine learning-based anomaly detection was introduced in v5.4 and went GA in v5.5:

[https://www.elastic.co/products/x-pack/machine-learning](https://www.elastic.co/products/x-pack/machine-learning)
