Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Anomaly Detection with the Elastic Stack
Search
Kosho Owa
December 15, 2016
Technology
1
1.8k
Anomaly Detection with the Elastic Stack
Prelert: Elastic Stackを利用した異常検知
Elastic{ON} Tour Tokyo 2016
Kosho Owa
December 15, 2016
Tweet
Share
More Decks by Kosho Owa
See All by Kosho Owa
Introducing Machine Learning for the Elastic Stack
kosho
2
12k
Elastic Stack X-Pack 5.0 for IT Security Workshop
kosho
1
310
Elastic Stack X-Pack 5.0 for IT Ops Workshop
kosho
0
330
[Developers Summit 2017] Anomaly Detection with the Elastic Stack
kosho
1
710
Getting Started with Elastic Cloud and Beats for Log Analytics
kosho
0
100
Elastic{ON} Seminar Tokyo 2016 Product Update
kosho
0
170
Introducing Elastic Cloud
kosho
0
76
Gearing Up for Elastic Stack, X-Pack 5.0 Releases
kosho
0
150
Elastic Stack Hands-on Workshop (EN)
kosho
1
160
Other Decks in Technology
See All in Technology
プロポーザルのコツ ~ Kaigi on Rails 2025 初参加で3名の登壇を実現 ~
naro143
1
160
AI ReadyなData PlatformとしてのAutonomous Databaseアップデート
oracle4engineer
PRO
0
230
PLaMoの事後学習を支える技術 / PFN LLMセミナー
pfn
PRO
9
4k
空間を設計する力を考える / 20251004 Naoki Takahashi
shift_evolve
PRO
4
440
Azure Well-Architected Framework入門
tomokusaba
1
350
社内お問い合わせBotの仕組みと学び
nish01
1
510
許しとアジャイル
jnuank
1
140
AI駆動開発を推進するためにサービス開発チームで 取り組んでいること
noayaoshiro
0
230
Exadata Database Service on Dedicated Infrastructure(ExaDB-D) UI スクリーン・キャプチャ集
oracle4engineer
PRO
3
5.5k
AWS Top Engineer、浮いてませんか? / As an AWS Top Engineer, Are You Out of Place?
yuj1osm
2
170
動画データのポテンシャルを引き出す! Databricks と AI活用への奮闘記(現在進行形)
databricksjapan
0
160
E2Eテスト設計_自動化のリアル___Playwrightでの実践とMCPの試み__AIによるテスト観点作成_.pdf
findy_eventslides
1
530
Featured
See All Featured
Building Flexible Design Systems
yeseniaperezcruz
329
39k
Designing for humans not robots
tammielis
254
26k
Typedesign – Prime Four
hannesfritz
42
2.8k
The Language of Interfaces
destraynor
162
25k
The Myth of the Modular Monolith - Day 2 Keynote - Rails World 2024
eileencodes
26
3.1k
How STYLIGHT went responsive
nonsquared
100
5.8k
jQuery: Nuts, Bolts and Bling
dougneiner
64
7.9k
Improving Core Web Vitals using Speculation Rules API
sergeychernyshev
19
1.2k
Automating Front-end Workflow
addyosmani
1371
200k
Side Projects
sachag
455
43k
Fight the Zombie Pattern Library - RWD Summit 2016
marcelosomers
234
17k
Gamification - CAS2011
davidbonilla
81
5.5k
Transcript
Prelert: Elastic StackΛར༻ͨ͠ҟৗݕ େྠ ߂ৄ | Kosho Owa Solutions Architect,
Elastic
*5ΦϖϨʔγϣϯ • ࣗͷγεςϜਖ਼ৗʹՔಇ͍ͯ͠Δ? • ͲͷΑ͏ʹᮢΛஅ͢Δ? • ͕ൃੜͨ࣌͠ʹɺͲͷΑ͏ʹݪҼΛݟ͚ͭΔ? 2
*5ηΩϡϦςΟ • ϚϧΣΞʹ৵ೖ͞Ε͍ͯΔγεςϜແ͍͔? • ϚϧΣΞ͕ͲͷΑ͏ʹײછΛ͔͛ͨ? • જࡏతʹڴҖͱͳΔ৫෦ͷϢʔβʔ୭͔? 3
ͦͷଞ • ͲͷΑ͏ʹɺଟ͘ͷछྨͷ࣌ܥྻσʔλͱ͖߹͏͔? • ਖ਼ৗʹՔಇ͍ͯ͠Δ? • Ͳͷަ௨ࣄނ͕࠷ौΛҾ͖ى͍ͯ͜͠Δ͔? 4
σʔλ͔Β༗ҙٛͳใΛݟ͚ͭΔํ๏ 5 Search Aggregations Visualization Machine Learning
t_900 - Dashboard New Add Save Open Share Options !
~ 3 years ago to ~ 3 years ago 900 - Actual 2013-09-18 00:00 2013-09-21 00:00 2013-09-24 00:00 2013-09-27 00:00 2013-09-30 00:00 2013-10-03 00:00 2013-10-06 00:00 2013-10-09 00:00 2013-10-12 00:00 0 1000000 2000000 3000000 4000000 5000000 6000000 7000000 8000000 Actual 900 - Moving Average 6000000 7000000 8000000 Moving Average Actual Anomaly " ҟৗݕͷνϟϨϯδ 6 1 3 2 4 2 2 2 2 week
ҠಈฏۉʹΑΔҟৗݕ 7 t_900 - Dashboard New Add Save Open Share
Options ! ~ 3 years ago to ~ 3 years ago 900 - Moving Average 2013-09-18 00:00 2013-09-21 00:00 2013-09-24 00:00 2013-09-27 00:00 2013-09-30 00:00 2013-10-03 00:00 2013-10-06 00:00 2013-10-09 00:00 2013-10-12 00:00 0 1000000 2000000 3000000 4000000 5000000 6000000 7000000 8000000 Moving Average Actual Anomaly 900 - Holt-Winters 8000000 9000000 HoltWinters Actual Anomaly "
)PMU8JOUFSTʹΑΔҟৗݕ 8 _900 - Dashboard New Add Save Open Share
Options ! ~ 3 years ago to ~ 3 years ago 900 - Holt-Winters 2013-09-18 00:00 2013-09-21 00:00 2013-09-24 00:00 2013-09-27 00:00 2013-09-30 00:00 2013-10-03 00:00 2013-10-06 00:00 2013-10-09 00:00 2013-10-12 00:00 0 1000000 2000000 3000000 4000000 5000000 6000000 7000000 8000000 9000000 HoltWinters Actual Anomaly ly timeline : detector Interval: Auto Sep 17 2013 Sep 19 2013 Sep 21 2013 Sep 23 2013 Sep 25 2013 Sep 27 2013 Sep 29 2013 Oct 1 2013 Oct 3 2013 Oct 5 2013 Oct 7 2013 Oct 9 2013 Oct 11 2013 non_zero_count "
1SFMFSUʹΑΔҟৗݕ 9 rer Jobs Summary view Explorer Connections Support !
" # $ September 15th 2013, 00:00:00.000 to October 13th All jobs * debug 900 Sep 17 2013 Sep 20 2013 Sep 23 2013 Sep 26 2013 Sep 29 2013 Oct 2 2013 Oct 5 2013 Oct 8 2013 Oct 11 2013 0 500000 1000000 1500000 2000000 Infl y timeline : detector Interval: Auto Sep 17 2013 Sep 20 2013 Sep 23 2013 Sep 26 2013 Sep 29 2013 Oct 2 2013 Oct 5 2013 Oct 8 2013 Oct 11 2013 non_zero_count All jobs * debug 900 Sep 17 2013 Sep 20 2013 Sep 23 2013 Sep 26 2013 Sep 29 2013 Oct 2 2013 Oct 5 2013 Oct 8 2013 Oct 11 2013 0 500000 1000000 1500000 2000000 Influ ly timeline : detector Interval: Auto Sep 17 2013 Sep 20 2013 Sep 23 2013 Sep 26 2013 Sep 29 2013 Oct 2 2013 Oct 5 2013 Oct 8 2013 Oct 11 2013 non_zero_count lies 1 3 2 4
ୈिͷΫϩʔζΞοϓ 10 orer Jobs Summary view Explorer Connections Support !
" # $ September 22nd 2013, 00:00:00.000 to September 29th 2 All jobs * l debug _900 Sep 22 09:00 Sep 22 21:00 Sep 23 09:00 Sep 23 21:00 Sep 24 09:00 Sep 24 21:00 Sep 25 09:00 Sep 25 21:00 Sep 26 09:00 Sep 26 21:00 Sep 27 09:00 Sep 27 21:00 Sep 28 09:00 Sep 28 21:00 0 500000 1000000 1500000 2000000 Influ aly timeline by: detector Interval: Auto Sep 22 09:00 Sep 22 21:00 Sep 23 09:00 Sep 23 21:00 Sep 24 09:00 Sep 24 21:00 Sep 25 09:00 Sep 25 21:00 Sep 26 09:00 Sep 26 21:00 Sep 27 09:00 Sep 27 21:00 Sep 28 09:00 Sep 28 21:00 non_zero_count 3 2
1SFMFSUͷςΫϊϩδʔ 11 σʔλʹજΉߦಈϞσϧΛ ࣗಈతʹڭࢣͳֶ͠श ݱࡏͷߦಈ͕༧ଌϞσϧͱ ݦஶʹҟͳΔ߹ʹ௨
Demo
%FNP*5ΦϖϨʔγϣϯ
%FNP*5ΦϖϨʔγϣϯ
%FNP*5ΦϖϨʔγϣϯ
%FNP*5ηΩϡϦςΟ
ϩʔυϚοϓ • ϕʔλ൛Λఏڙத (prelert.com) • Elastic StackͱͷڧݻͳΠϯςάϨʔγϣϯ͕ਐߦத • 2017্ظͷϦϦʔεΛඪ 17