Create Jobs

The create job API enables you to instantiate a job.


PUT _xpack/ml/anomaly_detectors/<job_id>

Path Parameters

job_id (required)
(string) Identifier for the job

Request Body

(object) The analysis configuration, which specifies how to analyze the data. See analysis configuration objects.
Optionally specifies runtime limits for the job. See analysis limits.
data_description (required)
(object) Describes the format of the input data. This object is required, but it can be empty ({}). See data description objects.
(string) An optional description of the job.
(object) This advanced configuration option stores model information along with the results. This adds overhead to the performance of the system and is not feasible for jobs with many entities, see Model Plot Config.
(long) The time in days that model snapshots are retained for the job. Older snapshots are deleted. The default value is 1 day. For more information about model snapshots, see Model Snapshot Resources.
(string) The name of the index in which to store the machine learning results. The default value is shared, which corresponds to the index name .ml-anomalies-shared.


You must have manage_ml, or manage cluster privileges to use this API. For more information, see Security Privileges.


The following example creates the it-ops-kpi job:

PUT _xpack/ml/anomaly_detectors/it-ops-kpi
    "description":"First simple job",
      "bucket_span": "5m",
      "latency": "0ms",
          "detector_description": "low_sum(events_per_min)",
          "field_name": "events_per_min"
    "data_description": {

When the job is created, you receive the following results:

  "job_id": "it-ops-kpi",
  "job_type": "anomaly_detector",
  "description": "First simple job",
  "create_time": 1491948238874,
  "analysis_config": {
    "bucket_span": "5m",
    "latency": "0ms",
    "detectors": [
        "detector_description": "low_sum(events_per_min)",
        "function": "low_sum",
        "field_name": "events_per_min",
        "detector_rules": [],
        "detector_index": 0
    "influencers": []
  "data_description": {
    "time_field": "@timestamp",
    "time_format": "epoch_ms"
  "model_snapshot_retention_days": 1,
  "results_index_name": "shared"