Count Functions

The X-Pack machine learning features include the following count functions:

  • count, high_count, low_count
  • non_zero_count, high_non_zero_count, low_non_zero_count
  • distinct_count, high_distinct_count, low_distinct_count

Count functions detect anomalies when the count of events in a bucket is anomalous.

Use non_zero_count functions if your data is sparse and you want to ignore cases where the bucket count is zero.

Use distinct_count functions to determine when the number of distinct values in one field is unusual, as opposed to the total count.

Use high-sided functions if you want to monitor unusually high event rates. Use low-sided functions if you want to look at drops in event rate.