# What is the ".ml-anomalies" and the ".ml-anomalies-shared"?

**URL:** <https://discuss.elastic.co/t/what-is-the-ml-anomalies-and-the-ml-anomalies-shared/197397>\
**Category:** Kibana\
**Tags:** elastic-stack-machine-learning\
**Created:** [August 29, 2019, 6:14pm UTC](https://discuss.elastic.co/t/what-is-the-ml-anomalies-and-the-ml-anomalies-shared/197397 "2019-08-29T18:14:29Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rosho](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rosho/32/51872_2.png) [@Rosho](https://discuss.elastic.co/u/Rosho)\
**Post date:** [August 29, 2019, 6:14pm UTC](https://discuss.elastic.co/t/what-is-the-ml-anomalies-and-the-ml-anomalies-shared/197397/1 "2019-08-29T18:14:29Z")

</div>

Hello

I found these 2 index patterns: ".ml-anomalies", ".ml-anomalies-shared" in Kibana when ticking "Include system indices".

What are those for?  
What is the difference?

---

<div class="post-metadata">

**Author:** ![BenTrent](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bentrent/32/33915_2.png) [@BenTrent](https://discuss.elastic.co/u/BenTrent)\
**Post date:** [August 29, 2019, 9:15pm UTC](https://discuss.elastic.co/t/what-is-the-ml-anomalies-and-the-ml-anomalies-shared/197397/2 "2019-08-29T21:15:42Z")

</div>

@Rosho

We have numerous concrete indices for storing Machine Learning results.

`.ml-anomalies-shared` is the default location for ALL machine learning jobs

For larger machine learning jobs, we give the option of allowing you to set the job to use its own index (see `results_index_name` in [ML PUT Job API](https://www.elastic.co/guide/en/elasticsearch/reference/6.8/ml-put-job.html)).

Those should be displayed as  
`.ml-anomalies-custom-<results_index_name>`. The Kibana job creation wizards give you a checkbox to select if the results should be in their own index. Kibana sets `results_index_name` to the configured job id.

As for `.ml-anomalies` I am not sure why you are seeing that index as an option. I do not think the machine learning plugin uses an index by that name. What version of the stack are you seeing this concrete index in?

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [August 30, 2019, 12:16am UTC](https://discuss.elastic.co/t/what-is-the-ml-anomalies-and-the-ml-anomalies-shared/197397/3 "2019-08-30T00:16:01Z")

</div>

He probably means the `.ml-anomalies-*` index pattern which is designed to match everything

---

<div class="post-metadata">

**Author:** ![Rosho](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rosho/32/51872_2.png) [@Rosho](https://discuss.elastic.co/u/Rosho)\
**Post date:** [August 30, 2019, 5:16pm UTC](https://discuss.elastic.co/t/what-is-the-ml-anomalies-and-the-ml-anomalies-shared/197397/4 "2019-08-30T17:16:55Z")

</div>

@BenTrent @richcollier

I am using the Kibana 6.8.2

I watched this tutorial on how to add a ML result to the dashboard.

> **[Time Series, Annotations, and Anomalies with Kibana](https://www.elastic.co/fr/blog/time-series-annotations-and-anomalies-with-kibana)**
>
> Add annotations to your time series chart directly from the anomalies detected by a machine learning job.

I followed the example and used that file (.ml-anomalies-\*) for a MULTIMETRIC job.  
Then later I used the same file for a POPULATION job. Is that alright? Or should I have used the ".ml-anomalies-shared"?

Where is that option that will allow me to set the job to use its own index? Is it the "Use dedicated index"?

 ![Capture](https://us1.discourse-cdn.com/elastic/original/3X/9/1/9120f53c6b0a7a577725547ada40046598e8c3f3.png)

---

<div class="post-metadata">

**Author:** ![BenTrent](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bentrent/32/33915_2.png) [@BenTrent](https://discuss.elastic.co/u/BenTrent)\
**Post date:** [August 30, 2019, 7:29pm UTC](https://discuss.elastic.co/t/what-is-the-ml-anomalies-and-the-ml-anomalies-shared/197397/5 "2019-08-30T19:29:18Z")

</div>

Yes, it is the `use dedicated index` checkbox.

As for whether to use `.ml-anomalies-*` vs `.ml-anomalies-shared`, that is entirely up to you. But using `.ml-anomalies-*` will cover the cases when a job has a dedicated results index.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 27, 2019, 7:29pm UTC](https://discuss.elastic.co/t/what-is-the-ml-anomalies-and-the-ml-anomalies-shared/197397/6 "2019-09-27T19:29:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
