elastic / elastic/stack-docs

Interpreting anomaly detection results

Open
#1,430 0 comments 0 reactions 0 assignees View on GitHub
:ml
Dominant language
Java
Stars
105
Forks
249
PR merge metrics
No merged PRs in 30d

Description

Our content about how to interpret anomaly detection job is currently spread about and it would be useful to see if it can be improved by pulling it together into a procedure that (ideally) could then be re-used in whole or in part in multiple solutions.

It should include:

- Differences between Anomaly Explorer and Single Metric Viewer (covered at high level in [tutorial](https://www.elastic.co/guide/en/machine-learning/current/ml-gs-results.html))
- Information about what you can glean from [influencers](https://www.elastic.co/guide/en/machine-learning/current/ml-influencers.html)
- Interpreting [multi-bucket](https://www.elastic.co/guide/en/machine-learning/current/ml-buckets.html#ml-bucket-results) anomalies
- A summary of the different types of results (e.g. model plot results, [influencer results](https://www.elastic.co/guide/en/machine-learning/current/ml-influencers.html#ml-influencer-results), [bucket results](https://www.elastic.co/guide/en/machine-learning/current/ml-buckets.html#ml-bucket-results), [record results](https://www.elastic.co/guide/en/elasticsearch/reference/7.4/ml-results-resource.html)
- Interpreting anomaly scores and how they are calculated and how they differ from probability.(covered at high level in [tutorial](https://www.elastic.co/guide/en/machine-learning/current/ml-gs-results.html))
- Meaning of "actual" and "typical" values (covered at high level in [tutorial](https://www.elastic.co/guide/en/machine-learning/current/ml-gs-results.html))

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.