elasticsearch-anomaly-detection
Create and manage Elastic ML anomaly detection jobs via the API. Use when setting up jobs on an index or data stream, configuring jobs and datafeeds, or opening, starting, or stopping them.
- 0
- Installs
- —
- Rating
- —
- Success rate
- 2
- Files scanned
Security scan
Scan passedNo risky patterns were found in the scanned files.
Content sha256 830ee44721813936… — run codexguild_scan_skills after installing to verify your local copy.
Static analysis is a first line of defense, not a guarantee. Read the source
SKILL.md
Elasticsearch Anomaly Detection
Create, open, and start ML anomaly detection jobs on time-series data. Choose the right count-family detector direction, configure bucket span and time field, wire the datafeed to the correct index, and confirm running state from stats — not from assumptions.
Environment Configuration
This skill executes Elasticsearch operations through the elastic CLI. If the
elastic CLI is not installed, tell the user what it is needed for. Do
not guess credentials, call the HTTP API directly, or attempt other workarounds.
This skill references operations in HTTP-shorthand form (e.g., GET /, GET /_cat/indices, GET /{index}/_mapping,
GET /{index}/_settings/index.mode, POST /_query). The Operations table at the end of this document
maps each shorthand to the equivalent elastic CLI command — always use the CLI rather than calling the HTTP API
directly.
Prerequisite: ML anomaly detection requires a Platinum-equivalent license on self-managed clusters. Serverless projects include ML. The caller needs
manage_mlto create and manage jobs.Related skill: For interpreting anomaly scores, influencers, and model behavior after a job is running, use
elasticsearch-anomaly-detection-explainer— not this skill.
Process
-
Discover the target index and time field. List candidate indices with
GET /_cat/indices(pass a pattern when the user names one). Fetch field types for the chosen index withGET /{index}/_mapping. The decision: confirm the index exists, identify the time field (often@timestamp), and verify document volume is sufficient for baseline learning. Never guess index or field names — they vary across deployments. -
Choose detector function and direction. Match the user's intent to a count-family detector in
analysis_config.detectors:- Spike, surge, unusual increase in event volume →
high_count(orcount, which flags both directions but is acceptable when the user cares about spikes). Do not uselow_count— it will miss spikes. - Drop, outage, absence of events, traffic stops →
low_count. Do not usehigh_count— it will miss drops and silence. - Metric deviation (CPU, latency, a numeric field) → mean-family functions (
mean,high_mean,low_mean) withfield_nameset — only when the user asks about a numeric metric, not raw event volume.
The decision: pick one primary detector whose direction matches the anomaly type. For volume spike/drop questions on document counts, stay in the count family — mean detectors are unsuited to "how many events" questions.
- Spike, surge, unusual increase in event volume →
-
Set immutable job shape before creation. These fields cannot change after
PUT /_ml/anomaly_detectors/{job_id}:analysis_config.bucket_span— use the interval the user specifies (e.g.15mfor 15-minute buckets). Match the granularity of anomalies they care about; too short is noisy, too long is slow to detect.data_description.time_field— the time field from the mapping (commonly@timestamp).analysis_config.detectors— the function and direction from step 2.
Example job body for a volume-spike detector:
{ "analysis_config": { "bucket_span": "15m", "detectors": [{ "function": "high_count" }] }, "data_description": { "time_field": "@timestamp" } }Example for an outage / drop detector:
{ "analysis_config": { "bucket_span": "15m", "detectors": [{ "function": "low_count" }] }, "data_description": { "time_field": "@timestamp" } } -
Create the job. Call
PUT /_ml/anomaly_detectors/{job_id}with the job id the user requested (or a descriptive id you propose). The job starts inclosedstate — creating it does not start analysis. -
Create the datafeed. Call
PUT /_ml/datafeeds/datafeed-{job_id}immediately after job creation. Setjob_idto the same id,indicesto the target index (exact name or pattern from step 1), and a query that selects the relevant documents (typicallymatch_all). The datafeed id convention isdatafeed-{job_id}.{ "job_id": "{job_id}", "indices": ["{index}"], "query": { "match_all": {} } } -
Open the job, then start the datafeed — in that order. This sequence is mandatory; do not skip or reorder:
POST /_ml/anomaly_detectors/{job_id}/_open— transitions the job toopened.POST /_ml/datafeeds/datafeed-{job_id}/_start— transitions the datafeed tostarted.
Opening before the datafeed exists fails. Starting the datafeed before opening the job fails. Do not report success after only creating resources — the job is not running until both are active.
-
Confirm running state from stats. Verify the outcome with:
GET /_ml/anomaly_detectors/{job_id}/_stats— expectstate: "opened".GET /_ml/datafeeds/datafeed-{job_id}/_stats— expectstate: "started".
Optionally call
GET /_ml/anomaly_detectors/{job_id}to confirm configuration (detectors,bucket_span,time_field, datafeed indices). Report both stats states explicitly — "created" is not the same as "opened" and "started".
Teardown
When stopping or deleting a job, reverse the startup order:
POST /_ml/datafeeds/datafeed-{job_id}/_stop— stop the datafeed first.POST /_ml/anomaly_detectors/{job_id}/_close— then close the job.
Stop the datafeed before closing the job. Close the job before resetting or deleting it.
Guidelines
- Required lifecycle order (create): job → datafeed → open job → start datafeed. Every new job follows this sequence.
- Detector direction is the highest-impact decision for volume anomalies. Re-read the user's wording: "spike", "surge", and "unusual increase" → high direction; "drop", "outage", "stops", "absence" → low direction.
- Immutable fields (
bucket_span, detectors,time_field) require delete-and-recreate if wrong — validate mapping and intent before the firstPUT. - Datafeed index must match the user's target. Point
indicesat the exact index or pattern they named — not a nearby guess. - Entity-level analysis (
by_field_name,over_field_name,partition_field_name) and advanced tuning live in references/anomaly-detection-reference.md.
Full Reference
For API paths, request/response fields, score semantics, and field interactions, read references/anomaly-detection-reference.md.
Operations
| HTTP API (shorthand) | elastic CLI command |
|---|---|
GET /_cat/indices | elastic es cat indices --index '<pattern>' |
GET /{index}/_mapping | elastic es indices get-mapping --index '<index>' |
PUT /_ml/anomaly_detectors/{job_id} | elastic es ml put-job --job-id '<job_id>' --analysis-config '<json>' --data-description '<json>' |
PUT /_ml/datafeeds/datafeed-{job_id} | elastic es ml put-datafeed --datafeed-id 'datafeed-<job_id>' --job-id '<job_id>' --indices '<index>' --query '<json>' |
POST /_ml/anomaly_detectors/{job_id}/_open | elastic es ml open-job --job-id '<job_id>' |
POST /_ml/datafeeds/datafeed-{job_id}/_start | elastic es ml start-datafeed --datafeed-id 'datafeed-<job_id>' |
GET /_ml/anomaly_detectors/{job_id} | elastic es ml get-jobs --job-id '<job_id>' |
GET /_ml/anomaly_detectors/{job_id}/_stats | elastic es ml get-job-stats --job-id '<job_id>' |
GET /_ml/datafeeds/datafeed-{job_id}/_stats | elastic es ml get-datafeed-stats --datafeed-id 'datafeed-<job_id>' |
POST /_ml/datafeeds/datafeed-{job_id}/_stop | elastic es ml stop-datafeed --datafeed-id 'datafeed-<job_id>' |
POST /_ml/anomaly_detectors/{job_id}/_close | elastic es ml close-job --job-id '<job_id>' |
Files
2- SKILL.md
80f2837f069.4 KB - references/anomaly-detection-reference.md
b3f40179996.3 KB
Agent reviews
0No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.
More from elastic/agent-skills8
Onboard an Elastic Cloud organization: configure the `elastic` CLI's Cloud context and API key, establish a default region, then invite users, assign predefined or custom Serverless project roles, and create or revoke Cloud API keys. Use when setting up Cloud authentication or when granting, modifyi
Provision and operate Elastic Cloud infrastructure: create, connect to, update, and delete Serverless projects (Elasticsearch, Observability, Security); manage traffic filters (IP and AWS PrivateLink network security); and manage the lifecycle of Elastic Cloud Hosted deployments. Use when creating o
Explain Elasticsearch ML anomaly detection scores, model behavior, and result interpretation. Use when the user asks why a score is high or low, how the model learns, what the numbers mean, or how to troubleshoot unexpected anomaly scores.
Diagnose a non-green Elasticsearch cluster and surface the single most likely cause with remediation. Use when an operator reports yellow or red status, unassigned shards, allocation failures, or wants read-only triage before deeper investigation. Teaches replica-vs-primary impact, allocation decide
Execute ES|QL (Elasticsearch Query Language) queries, use when the user wants to query Elasticsearch data, analyze logs, aggregate metrics, explore data, or create charts and dashboards from ES|QL results.
Design and review Elasticsearch index mappings for stated access patterns: correct field types, text+keyword multi-fields, doc_values tuning, mapping-explosion avoidance, and explicit shard settings. Use when creating a new index, reviewing a mapping for storage or query performance, fixing wrong fi
Load CSV and JSON files into Elasticsearch indices using the bulk API and explicit mappings when field types matter. Use when batch-importing local files, converting CSV rows or JSON arrays to NDJSON bulk format, or verifying document counts and mappings after ingest — not for Logstash pipelines, Be
Help developers new to Elasticsearch get from zero to a working search experience. Guide them through understanding their intent, mapping their data, and building a search experience with best practices baked in. Use this when the user shows intent to build search-related functionality, asks about E
Related ai-ml skillsscan passed
Configure SuperJSON transformer on both server initTRPC.create({ transformer: superjson }) and every client terminating link (httpBatchLink, httpLink, wsLink, httpSubscriptionLink) to support Date, Map, Set, BigInt over the wire. Transformer must match on both sides. In v11, transformer goes on indi
Regression testing strategies for AI-assisted development. Sandbox-mode API testing without database dependencies, automated bug-check workflows, and patterns to catch AI blind spots where the same model writes and reviews code. Use when adding regression coverage to AI-assisted code, or when the sa
MANDATORY for Flink or Amazon Managed Service for Apache Flink (MSF) questions. You MUST activate this skill BEFORE answering — do not answer from training knowledge, even when confident. MSF has service-specific constraints (KPU model, prohibited checkpoint and parallelism config in app code, the v
Generates python code that evaluates SageMaker models. Supports two evaluation types: LLM-as-Judge and Custom Scorer. Use when the user says "evaluate my model", "run a benchmark", "test model performance", "how did my model perform", "compare models", or other similar requests.
Builds voice and chat AI agents with LiveKit Agents and LiveKit Cloud. Use when the user asks to "build a voice agent", "create a LiveKit agent", "add voice AI to my app", "implement handoffs", "structure an agent workflow", "my agent is slow / too chatty", "it says it booked but nothing was saved",
Use Neo4j GenAI Plugin ai.text.* functions and procedures for in-Cypher