NOTE: You are looking at documentation for an older release. For the latest information, see the current release documentation.
The Elastic machine learning anomaly detection feature automatically model the normal behavior of your time series data — learning trends, periodicity, and more — in real time to identify anomalies, streamline root cause analysis, and reduce false positives.
Anomaly detection run in and scale with Elasticsearch, and include an intuitive UI on the Kibana Machine Learning page for creating anomaly detection jobs and understanding results.
If you have a license that includes the machine learning features, you can create anomaly detection jobs and manage jobs and datafeeds from the Job Management pane:
The Anomaly Explorer and Single Metric Viewer display the results of your anomaly detection jobs. For example:
You can optionally add annotations by drag-selecting a period of time in the Single Metric Viewer and adding a description. For example, you can add an explanation for anomalies in that time period or provide notes about what is occurring in your operational environment at that time:
In some circumstances, annotations are also added automatically. For example, if the anomaly detection job detects that there is missing data, it annotates the affected time period. For more information, see Handling delayed data. The Job Management pane shows the full list of annotations for each job.
The Kibana machine learning features use pop-ups. You must configure your web browser so that it does not block pop-up windows or create an exception for your Kibana URL.
For more information about the anomaly detection feature, see https://www.elastic.co/what-is/elastic-stack-machine-learning and Machine learning in the Elastic Stack.