# \#elastic-stack-machine-learning

**URL:** https://discuss.elastic.co/tag/elastic-stack-machine-learning/9.md

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

---

## [Can't deploy model on ML node due to insufficient memory](https://discuss.elastic.co/t/cant-deploy-model-on-ml-node-due-to-insufficient-memory/387871)

<div class="topic-metadata">

**Author:** [@Giorgi\_Jambazishvili](https://discuss.elastic.co/u/Giorgi_Jambazishvili)\
**Replies:** 0\
**Last updated:** [July 8, 2026, 11:23am UTC](https://discuss.elastic.co/t/cant-deploy-model-on-ml-node-due-to-insufficient-memory/387871 "2026-07-08T11:23:02Z")

</div>

I am using Elasticsearch cloud. I currently host the free-tier ML node, but the same behavior occurs on the next available tier (node w/ 2GB of memory). I am trying to deploy the E5 embedding model, preferably base, but…

---

## [Eland-imported naver/splade-v3 text\_expansion produces much smaller sparse vectors and worse ranking than local SentenceTransformers SparseEncoder](https://discuss.elastic.co/t/eland-imported-naver-splade-v3-text-expansion-produces-much-smaller-sparse-vectors-and-worse-ranking-than-local-sentencetransformers-sparseencoder/386819)

<div class="topic-metadata">

**Author:** [@alrolo3](https://discuss.elastic.co/u/alrolo3)\
**Replies:** 0\
**Last updated:** [June 11, 2026, 9:39pm UTC](https://discuss.elastic.co/t/eland-imported-naver-splade-v3-text-expansion-produces-much-smaller-sparse-vectors-and-worse-ranking-than-local-sentencetransformers-sparseencoder/386819 "2026-06-11T21:39:41Z")

</div>

Eland-imported naver/splade-v3 text\_expansion produces much smaller sparse vectors and worse ranking than local SentenceTransformers SparseEncoder Environment Elasticsearch version: 9.4.2 Eland Docker image used: docke…

---

## [ML jobs has no warnings or errors but message seems to be lagging](https://discuss.elastic.co/t/ml-jobs-has-no-warnings-or-errors-but-message-seems-to-be-lagging/385542)

<div class="topic-metadata">

**Author:** [@Whoami1980](https://discuss.elastic.co/u/Whoami1980)\
**Replies:** 6\
**Last updated:** [March 30, 2026, 5:55am UTC](https://discuss.elastic.co/t/ml-jobs-has-no-warnings-or-errors-but-message-seems-to-be-lagging/385542 "2026-03-30T05:55:08Z")

</div>

In one of our ML jobs. There doesnt appears to be any errors or warning in the job message. However the latest\_record\_timestamp is lagging behind the current\_timestamp KIndly advice how we can further look into this. …

---

## [Unable to find job message fields in ".ml-anomalies\*" index](https://discuss.elastic.co/t/unable-to-find-job-message-fields-in-ml-anomalies-index/385537)

<div class="topic-metadata">

**Author:** [@Whoami1980](https://discuss.elastic.co/u/Whoami1980)\
**Replies:** 4\
**Last updated:** [March 23, 2026, 9:20am UTC](https://discuss.elastic.co/t/unable-to-find-job-message-fields-in-ml-anomalies-index/385537 "2026-03-23T09:20:57Z")

</div>

Machine Learning \>\> Anomaly Detection \>\> Jobs I am trying to come out with an ESQL query to consolidate all job messages that is non-info. warning or errors. Example of message Time Node Message 202X-XX-XX 16:24…

---

## [Anomaly Detection Jobs - Various warning messages](https://discuss.elastic.co/t/anomaly-detection-jobs-various-warning-messages/385501)

<div class="topic-metadata">

**Author:** [@Whoami1980](https://discuss.elastic.co/u/Whoami1980)\
**Replies:** 3\
**Last updated:** [March 18, 2026, 9:49am UTC](https://discuss.elastic.co/t/anomaly-detection-jobs-various-warning-messages/385501 "2026-03-18T09:49:02Z")

</div>

We are seeing various warning message below. Is there a guide to kickstart how we can kick start our troubleshooting? Warning datafeed is encountering errors submitting data for analysis exception while flushing jobs …

---

## [Dashboard anomaly score is not what we wanted](https://discuss.elastic.co/t/dashboard-anomaly-score-is-not-what-we-wanted/385336)

<div class="topic-metadata">

**Author:** [@Whoami1980](https://discuss.elastic.co/u/Whoami1980)\
**Replies:** 1\
**Last updated:** [March 4, 2026, 5:38pm UTC](https://discuss.elastic.co/t/dashboard-anomaly-score-is-not-what-we-wanted/385336 "2026-03-04T17:38:49Z")

</div>

We create a dashboard which return a single column to show actual, typical, anomaly score Apparently, the actual is the highest(actual) the typical is the highest(typical) The anomaly score is calculated based on the t…

---

## [Anomoly detection jobs. latest timestamp is updating but more than 2 months back](https://discuss.elastic.co/t/anomoly-detection-jobs-latest-timestamp-is-updating-but-more-than-2-months-back/385311)

<div class="topic-metadata">

**Author:** [@Whoami1980](https://discuss.elastic.co/u/Whoami1980)\
**Replies:** 3\
**Last updated:** [March 4, 2026, 5:15pm UTC](https://discuss.elastic.co/t/anomoly-detection-jobs-latest-timestamp-is-updating-but-more-than-2-months-back/385311 "2026-03-04T17:15:09Z")

</div>

Being a newbie to ML. Can anyone advice where I should start troubleshooting? job-name:noise-reduction-system-metrics-consolidated job state: opened. memory status: ok. latest timestamp is updating but more than 2 mo…

---

## [How to apply ILM to ML indices? If not possible what,s the workaround?](https://discuss.elastic.co/t/how-to-apply-ilm-to-ml-indices-if-not-possible-what-s-the-workaround/385310)

<div class="topic-metadata">

**Author:** [@Whoami1980](https://discuss.elastic.co/u/Whoami1980)\
**Replies:** 1\
**Last updated:** [March 3, 2026, 7:31pm UTC](https://discuss.elastic.co/t/how-to-apply-ilm-to-ml-indices-if-not-possible-what-s-the-workaround/385310 "2026-03-03T19:31:37Z")

</div>

Understand that ILM cannot be used on ML results indices. ILM is used on the ML state index out-of-the-box. Seems like this is a long open enhancement. \[ML\] Add an ML results index rollover endpoint · Issue #29946 · el…

---

## [ML rules How to handle timezone (UTC GMT-3) and alert duration in notifications?](https://discuss.elastic.co/t/ml-rules-how-to-handle-timezone-utc-gmt-3-and-alert-duration-in-notifications/384089)

<div class="topic-metadata">

**Author:** [@sguerrero](https://discuss.elastic.co/u/sguerrero)\
**Replies:** 0\
**Last updated:** [December 15, 2025, 5:55pm UTC](https://discuss.elastic.co/t/ml-rules-how-to-handle-timezone-utc-gmt-3-and-alert-duration-in-notifications/384089 "2025-12-15T17:55:27Z")

</div>

Hello community, We are currently using kibana machine learning anomaly detection alerts (anomaly detection jobs) with email actions triggered “for each alert \> on status change”. We have two related requirements regar…

---

## [Unable to load a trained model on ML node with sufficient memory](https://discuss.elastic.co/t/unable-to-load-a-trained-model-on-ml-node-with-sufficient-memory/383252)

<div class="topic-metadata">

**Author:** [@gueri](https://discuss.elastic.co/u/gueri)\
**Replies:** 0\
**Last updated:** [November 5, 2025, 5:52pm UTC](https://discuss.elastic.co/t/unable-to-load-a-trained-model-on-ml-node-with-sufficient-memory/383252 "2025-11-05T17:52:09Z")

</div>

Hello Here is the scenario. I have 2 ML nodes with 8 procs/64 Gb on Elastic 8.15.3. I start by loading a large bge\_m3 model with 1 allocation and 1 thread. :slight\_smile: As you can see on picture, one node had a …

---

## [Trial Extension Needed for Self-Hosted ML POC](https://discuss.elastic.co/t/trial-extension-needed-for-self-hosted-ml-poc/383202)

<div class="topic-metadata">

**Author:** [@EUphorik](https://discuss.elastic.co/u/EUphorik)\
**Replies:** 0\
**Last updated:** [November 4, 2025, 10:24am UTC](https://discuss.elastic.co/t/trial-extension-needed-for-self-hosted-ml-poc/383202 "2025-11-04T10:24:37Z")

</div>

Hello Elastic Team, We are mid-way through an urgent Proof of Concept (POC) involving a self-hosted deployment, specifically focusing on validating the Kibana Machine Learning (ML) module. Our trial license for Elastic…

---

## [No sufficient capacity to run baai\_bge\_m3 model](https://discuss.elastic.co/t/no-sufficient-capacity-to-run-baai-bge-m3-model/382693)

<div class="topic-metadata">

**Author:** [@gueri](https://discuss.elastic.co/u/gueri)\
**Replies:** 4\
**Last updated:** [November 3, 2025, 1:37pm UTC](https://discuss.elastic.co/t/no-sufficient-capacity-to-run-baai-bge-m3-model/382693 "2025-11-03T13:37:30Z")

</div>

Hi, My ML configuration is 2 nodes with this configuration for each node : ml.allocated\_processors\_double 8.0 ml.machine\_memory 62.4GB ml.config\_version 12.0.0 ml.max\_jvm\_size 4GB ml.allocated\_processors 8 I alr…

---

## [Understanding time\_in\_millis for ingest pipeline running embeddings](https://discuss.elastic.co/t/understanding-time-in-millis-for-ingest-pipeline-running-embeddings/382249)

<div class="topic-metadata">

**Author:** [@gueri](https://discuss.elastic.co/u/gueri)\
**Replies:** 2\
**Last updated:** [September 30, 2025, 1:32pm UTC](https://discuss.elastic.co/t/understanding-time-in-millis-for-ingest-pipeline-running-embeddings/382249 "2025-09-30T13:32:32Z")

</div>

Hi, I try to figured out the meaning of time\_in\_millis field about my ingest pipelines running embeddings. time\_in\_millis (integer) Total time, in milliseconds, spent preprocessing documents in the ingest pipeline. I…

---

## [Best practices for preprocessing data and monitoring resource usage in predefined ML jobs (security:host)](https://discuss.elastic.co/t/best-practices-for-preprocessing-data-and-monitoring-resource-usage-in-predefined-ml-jobs-security-host/382320)

<div class="topic-metadata">

**Author:** [@ilyes](https://discuss.elastic.co/u/ilyes)\
**Replies:** 0\
**Last updated:** [September 30, 2025, 1:31pm UTC](https://discuss.elastic.co/t/best-practices-for-preprocessing-data-and-monitoring-resource-usage-in-predefined-ml-jobs-security-host/382320 "2025-09-30T13:31:32Z")

</div>

Question 1: I am planning to use the predefined ML job from the security:host module. To avoid overloading the ML model with too much data, what would be the best approach in terms of data preprocessing? Should I fir…

---

## [\[v8.17.1\] Bug in Semantic Reranking using Vertex AI?](https://discuss.elastic.co/t/v8-17-1-bug-in-semantic-reranking-using-vertex-ai/380389)

<div class="topic-metadata">

**Author:** [@ik-southpole](https://discuss.elastic.co/u/ik-southpole)\
**Replies:** 2\
**Last updated:** [July 30, 2025, 7:53am UTC](https://discuss.elastic.co/t/v8-17-1-bug-in-semantic-reranking-using-vertex-ai/380389 "2025-07-30T07:53:21Z")

</div>

Good day, I am implementing a semantic ranking in v8.17.1 using Vertex AI (model semantic-ranker-default@latest) and I am facing some potentially strange behaviour. Context I followed Semantic reranking in Elasticsearc…

---

## [ No Observable Difference Between BBQ and Default Configurations in Elasticsearch – Help with Index Size Comparison](https://discuss.elastic.co/t/no-observable-difference-between-bbq-and-default-configurations-in-elasticsearch-help-with-index-size-comparison/377817)

<div class="topic-metadata">

**Author:** [@mohab\_ghobashy](https://discuss.elastic.co/u/mohab_ghobashy)\
**Replies:** 15\
**Last updated:** [July 2, 2025, 3:03pm UTC](https://discuss.elastic.co/t/no-observable-difference-between-bbq-and-default-configurations-in-elasticsearch-help-with-index-size-comparison/377817 "2025-07-02T15:03:15Z")

</div>

I've been running some tests on Better Binary Quantization (BBQ) in Elasticsearch and comparing it with the default configuration for dense vectors, but I'm not observing the expected differences in disk size or search p…

---

## [Elasticsearch Machine Learning Architecture and Requirements](https://discuss.elastic.co/t/elasticsearch-machine-learning-architecture-and-requirements/379358)

<div class="topic-metadata">

**Author:** [@Wei\_Li](https://discuss.elastic.co/u/Wei_Li)\
**Replies:** 1\
**Last updated:** [June 23, 2025, 6:47pm UTC](https://discuss.elastic.co/t/elasticsearch-machine-learning-architecture-and-requirements/379358 "2025-06-23T18:47:10Z")

</div>

Hi, I'm looking into integrating machine learning capabilities with Elasticsearch and have a few questions regarding architectural considerations and prerequisites for ML features. 1.Architectural Placement of ML Compo…

---

## [Failed to fetch frequent\_item\_sets in log rate analysis](https://discuss.elastic.co/t/failed-to-fetch-frequent-item-sets-in-log-rate-analysis/378492)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 0\
**Last updated:** [May 24, 2025, 9:00pm UTC](https://discuss.elastic.co/t/failed-to-fetch-frequent-item-sets-in-log-rate-analysis/378492 "2025-05-24T21:00:26Z")

</div>

Good evening, When I add log rate analysis to a dashboard in Elastic Security serverless, I see the following error: The following error occurred running the analysis. Failed to fetch frequent\_item\_sets. Anyone wi…

---

## [Deploy text embedding model via terraform](https://discuss.elastic.co/t/deploy-text-embedding-model-via-terraform/373074)

<div class="topic-metadata">

**Author:** [@Jaroslav\_Nejedly](https://discuss.elastic.co/u/Jaroslav_Nejedly)\
**Replies:** 2\
**Last updated:** [May 22, 2025, 11:14am UTC](https://discuss.elastic.co/t/deploy-text-embedding-model-via-terraform/373074 "2025-05-22T11:14:07Z")

</div>

Hi! What is the best way to deploy a text embedding model using Terraform? (If you think it should not be done via Terraform at all: What is the best way to automatically deploy a text embedding model to ensure it's alw…

---

## [Why Are Typical Values Negative or Missing in high\_sum Anomaly Detection in Elasticsearch?](https://discuss.elastic.co/t/why-are-typical-values-negative-or-missing-in-high-sum-anomaly-detection-in-elasticsearch/378196)

<div class="topic-metadata">

**Author:** [@Jordan\_Queiroz](https://discuss.elastic.co/u/Jordan_Queiroz)\
**Replies:** 0\
**Last updated:** [May 15, 2025, 6:30pm UTC](https://discuss.elastic.co/t/why-are-typical-values-negative-or-missing-in-high-sum-anomaly-detection-in-elasticsearch/378196 "2025-05-15T18:30:09Z")

</div>

Hello, everyone. I have a machine learning job that analyzes a numeric field where values are always greater than or equal to 0. The analysis function I'm using is high\_sum, and the field type is float. The machine lea…

---

## [How can APM anomaly detection be fine-tuned or adjusted to effectively address periodic fluctuations in service metrics?](https://discuss.elastic.co/t/how-can-apm-anomaly-detection-be-fine-tuned-or-adjusted-to-effectively-address-periodic-fluctuations-in-service-metrics/376610)

<div class="topic-metadata">

**Author:** [@arT1](https://discuss.elastic.co/u/arT1)\
**Replies:** 2\
**Last updated:** [April 1, 2025, 8:49am UTC](https://discuss.elastic.co/t/how-can-apm-anomaly-detection-be-fine-tuned-or-adjusted-to-effectively-address-periodic-fluctuations-in-service-metrics/376610 "2025-04-01T08:49:21Z")

</div>

Elastic Stack v8.13.3 Use the Elastic APM monitoring service and enable APM Machine Learning (ML). My service metrics data exhibits a regular pattern, with a higher number of visits during weekdays and a significantly l…

---

## [Semantic search with the new semantic\_text field](https://discuss.elastic.co/t/semantic-search-with-the-new-semantic-text-field/367169)

<div class="topic-metadata">

**Author:** [@JdKock](https://discuss.elastic.co/u/JdKock)\
**Replies:** 12\
**Last updated:** [March 21, 2025, 8:39am UTC](https://discuss.elastic.co/t/semantic-search-with-the-new-semantic-text-field/367169 "2025-03-21T08:39:19Z")

</div>

I did some testing with Elser and after that I used the E5 model to play around with semantic search. I use the knn search to create a query on multiple embedding fields. I also looked at the retrievers to create a hybri…

---

## [Log Visibility Issue for sfd-ui-node-server-dev Index in ELK](https://discuss.elastic.co/t/log-visibility-issue-for-sfd-ui-node-server-dev-index-in-elk/375458)

<div class="topic-metadata">

**Author:** [@vikascateina](https://discuss.elastic.co/u/vikascateina)\
**Replies:** 0\
**Last updated:** [March 5, 2025, 12:49pm UTC](https://discuss.elastic.co/t/log-visibility-issue-for-sfd-ui-node-server-dev-index-in-elk/375458 "2025-03-05T12:49:36Z")

</div>

We've encountered an issue with log visibility for the ui-node-dev index in our ELK server environment. This index uses the pattern ui-node-dev, whereas other indices, such as account-data-api-env, follow patterns like a…

---

## [Embedding generation using E5 failing for some records](https://discuss.elastic.co/t/embedding-generation-using-e5-failing-for-some-records/374090)

<div class="topic-metadata">

**Author:** [@Carlos\_Fernando\_Palm](https://discuss.elastic.co/u/Carlos_Fernando_Palm)\
**Replies:** 1\
**Last updated:** [February 20, 2025, 9:45am UTC](https://discuss.elastic.co/t/embedding-generation-using-e5-failing-for-some-records/374090 "2025-02-20T09:45:12Z")

</div>

I am trying to use the E5 model to generate embeddings for some documents. I used a reindex to generate the embeddings: POST \_reindex?wait\_for\_completion=false { "source": { "index": "source\_index", "size": 5…

---

## [Reindex with embeddings](https://discuss.elastic.co/t/reindex-with-embeddings/374088)

<div class="topic-metadata">

**Author:** [@Carlos\_Fernando\_Palm](https://discuss.elastic.co/u/Carlos_Fernando_Palm)\
**Replies:** 1\
**Last updated:** [February 5, 2025, 2:30am UTC](https://discuss.elastic.co/t/reindex-with-embeddings/374088 "2025-02-05T02:30:49Z")

</div>

I was trying to use the E5 model to generate embeddings for non english documents and I created a field that was a sparse\_vector. The index where I changed the mapping already has a sparse\_vector for another embedding a…

---

## [Use ELSER on data already in elastic](https://discuss.elastic.co/t/use-elser-on-data-already-in-elastic/373911)

<div class="topic-metadata">

**Author:** [@Carlos\_Fernando\_Palm](https://discuss.elastic.co/u/Carlos_Fernando_Palm)\
**Replies:** 2\
**Last updated:** [February 4, 2025, 8:15pm UTC](https://discuss.elastic.co/t/use-elser-on-data-already-in-elastic/373911 "2025-02-04T20:15:04Z")

</div>

I was going through the documentation for the ELSER model and I keep seeing that when using an inference point the model is applied to the data at ingestion time. Is there a way to populate the semantic\_text field for da…

---

## [Using reindex to generate embeddings from nested field](https://discuss.elastic.co/t/using-reindex-to-generate-embeddings-from-nested-field/373957)

<div class="topic-metadata">

**Author:** [@Carlos\_Fernando\_Palm](https://discuss.elastic.co/u/Carlos_Fernando_Palm)\
**Replies:** 1\
**Last updated:** [February 3, 2025, 10:03am UTC](https://discuss.elastic.co/t/using-reindex-to-generate-embeddings-from-nested-field/373957 "2025-02-03T10:03:41Z")

</div>

Hello! I was reading this: And I tried to apply the idea of using a reindex command together with an ingest pipeline to generate the embeddings of data already inside an elastic index. Now I defined the ingest pipeli…

---

## [Webhook Body for Machine Learning Alerts](https://discuss.elastic.co/t/webhook-body-for-machine-learning-alerts/373416)

<div class="topic-metadata">

**Author:** [@catarina](https://discuss.elastic.co/u/catarina)\
**Replies:** 2\
**Last updated:** [January 28, 2025, 3:04pm UTC](https://discuss.elastic.co/t/webhook-body-for-machine-learning-alerts/373416 "2025-01-28T15:04:33Z")

</div>

Hello Elastic Community, I’ve set up an advanced Machine Learning job to detect anomalies in user logins, with 6 detectors focusing on unusual source.ip, country, hostname, hour, and time of the week per user. I create…

---

## [Kibana Anomaly Alerts by PartitionField](https://discuss.elastic.co/t/kibana-anomaly-alerts-by-partitionfield/373133)

<div class="topic-metadata">

**Author:** [@jlrivera81](https://discuss.elastic.co/u/jlrivera81)\
**Replies:** 3\
**Last updated:** [January 16, 2025, 6:09pm UTC](https://discuss.elastic.co/t/kibana-anomaly-alerts-by-partitionfield/373133 "2025-01-16T18:09:21Z")

</div>

I currently have a working anomaly detection job for which i have configured my detector as: high\_count over Supervisor.routine.name partitionfield=Supervisor.resource.type For my alerts, I'd like to get an alert for t…

---

## [Anomaly detection for web site visitor surge (sparse data)](https://discuss.elastic.co/t/anomaly-detection-for-web-site-visitor-surge-sparse-data/372033)

<div class="topic-metadata">

**Author:** [@J\_Reinhardt](https://discuss.elastic.co/u/J_Reinhardt)\
**Replies:** 1\
**Last updated:** [December 17, 2024, 3:31pm UTC](https://discuss.elastic.co/t/anomaly-detection-for-web-site-visitor-surge-sparse-data/372033 "2024-12-17T15:31:20Z")

</div>

I'm trying to use elastic anomaly detection to identify when a surge in website visitor activity occurs for a particular IP address. The data set is really simple, it just shows the number of times an IP address has vis…

[Next page](https://discuss.elastic.co/tag/elastic-stack-machine-learning/9.md?match_all_tags=true&page=1&tags%5B%5D=elastic-stack-machine-learning)
