Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Anomaly Detection with the Elastic Stack
Search
Kosho Owa
December 15, 2016
Technology
1
1.8k
Anomaly Detection with the Elastic Stack
Prelert: Elastic Stackを利用した異常検知
Elastic{ON} Tour Tokyo 2016
Kosho Owa
December 15, 2016
Tweet
Share
More Decks by Kosho Owa
See All by Kosho Owa
Introducing Machine Learning for the Elastic Stack
kosho
2
12k
Elastic Stack X-Pack 5.0 for IT Security Workshop
kosho
1
320
Elastic Stack X-Pack 5.0 for IT Ops Workshop
kosho
0
330
[Developers Summit 2017] Anomaly Detection with the Elastic Stack
kosho
1
710
Getting Started with Elastic Cloud and Beats for Log Analytics
kosho
0
100
Elastic{ON} Seminar Tokyo 2016 Product Update
kosho
0
170
Introducing Elastic Cloud
kosho
0
76
Gearing Up for Elastic Stack, X-Pack 5.0 Releases
kosho
0
150
Elastic Stack Hands-on Workshop (EN)
kosho
1
160
Other Decks in Technology
See All in Technology
AIの個性を理解し、指揮する
shoota
3
590
ソースを読む時の思考プロセスの例-MkDocs
sat
PRO
1
350
CLIPでマルチモーダル画像検索 →とても良い
wm3
2
710
デザインとエンジニアリングの架け橋を目指す OPTiMのデザインシステム「nucleus」の軌跡と広げ方
optim
0
130
ヘンリー会社紹介資料(エンジニア向け) / company deck for engineer
henryofficial
0
440
仕様駆動開発を実現する上流工程におけるAIエージェント活用
sergicalsix
10
5.1k
初海外がre:Inventだった人間の感じたこと
tommy0124
1
150
境界線が消える世界におけるQAエンジニアのキャリアの可能性を考える / Considering the Career Possibilities for QA Engineers
mii3king
2
110
DMMの検索システムをSolrからElasticCloudに移行した話
hmaa_ryo
0
320
猫でもわかるAmazon Q Developer CLI 解体新書
kentapapa
1
220
文字列操作の達人になる ~ Kotlinの文字列の便利な世界 ~ - Kotlin fest 2025
tomorrowkey
2
300
オブザーバビリティが育むシステム理解と好奇心
maruloop
3
1.9k
Featured
See All Featured
The Art of Delivering Value - GDevCon NA Keynote
reverentgeek
16
1.7k
Leading Effective Engineering Teams in the AI Era
addyosmani
7
680
Facilitating Awesome Meetings
lara
57
6.6k
Code Reviewing Like a Champion
maltzj
526
40k
What’s in a name? Adding method to the madness
productmarketing
PRO
24
3.7k
4 Signs Your Business is Dying
shpigford
186
22k
Imperfection Machines: The Place of Print at Facebook
scottboms
269
13k
BBQ
matthewcrist
89
9.9k
ReactJS: Keep Simple. Everything can be a component!
pedronauck
666
130k
Code Review Best Practice
trishagee
72
19k
The Cost Of JavaScript in 2023
addyosmani
55
9.1k
CoffeeScript is Beautiful & I Never Want to Write Plain JavaScript Again
sstephenson
162
15k
Transcript
Prelert: Elastic StackΛར༻ͨ͠ҟৗݕ େྠ ߂ৄ | Kosho Owa Solutions Architect,
Elastic
*5ΦϖϨʔγϣϯ • ࣗͷγεςϜਖ਼ৗʹՔಇ͍ͯ͠Δ? • ͲͷΑ͏ʹᮢΛஅ͢Δ? • ͕ൃੜͨ࣌͠ʹɺͲͷΑ͏ʹݪҼΛݟ͚ͭΔ? 2
*5ηΩϡϦςΟ • ϚϧΣΞʹ৵ೖ͞Ε͍ͯΔγεςϜແ͍͔? • ϚϧΣΞ͕ͲͷΑ͏ʹײછΛ͔͛ͨ? • જࡏతʹڴҖͱͳΔ৫෦ͷϢʔβʔ୭͔? 3
ͦͷଞ • ͲͷΑ͏ʹɺଟ͘ͷछྨͷ࣌ܥྻσʔλͱ͖߹͏͔? • ਖ਼ৗʹՔಇ͍ͯ͠Δ? • Ͳͷަ௨ࣄނ͕࠷ौΛҾ͖ى͍ͯ͜͠Δ͔? 4
σʔλ͔Β༗ҙٛͳใΛݟ͚ͭΔํ๏ 5 Search Aggregations Visualization Machine Learning
t_900 - Dashboard New Add Save Open Share Options !
~ 3 years ago to ~ 3 years ago 900 - Actual 2013-09-18 00:00 2013-09-21 00:00 2013-09-24 00:00 2013-09-27 00:00 2013-09-30 00:00 2013-10-03 00:00 2013-10-06 00:00 2013-10-09 00:00 2013-10-12 00:00 0 1000000 2000000 3000000 4000000 5000000 6000000 7000000 8000000 Actual 900 - Moving Average 6000000 7000000 8000000 Moving Average Actual Anomaly " ҟৗݕͷνϟϨϯδ 6 1 3 2 4 2 2 2 2 week
ҠಈฏۉʹΑΔҟৗݕ 7 t_900 - Dashboard New Add Save Open Share
Options ! ~ 3 years ago to ~ 3 years ago 900 - Moving Average 2013-09-18 00:00 2013-09-21 00:00 2013-09-24 00:00 2013-09-27 00:00 2013-09-30 00:00 2013-10-03 00:00 2013-10-06 00:00 2013-10-09 00:00 2013-10-12 00:00 0 1000000 2000000 3000000 4000000 5000000 6000000 7000000 8000000 Moving Average Actual Anomaly 900 - Holt-Winters 8000000 9000000 HoltWinters Actual Anomaly "
)PMU8JOUFSTʹΑΔҟৗݕ 8 _900 - Dashboard New Add Save Open Share
Options ! ~ 3 years ago to ~ 3 years ago 900 - Holt-Winters 2013-09-18 00:00 2013-09-21 00:00 2013-09-24 00:00 2013-09-27 00:00 2013-09-30 00:00 2013-10-03 00:00 2013-10-06 00:00 2013-10-09 00:00 2013-10-12 00:00 0 1000000 2000000 3000000 4000000 5000000 6000000 7000000 8000000 9000000 HoltWinters Actual Anomaly ly timeline : detector Interval: Auto Sep 17 2013 Sep 19 2013 Sep 21 2013 Sep 23 2013 Sep 25 2013 Sep 27 2013 Sep 29 2013 Oct 1 2013 Oct 3 2013 Oct 5 2013 Oct 7 2013 Oct 9 2013 Oct 11 2013 non_zero_count "
1SFMFSUʹΑΔҟৗݕ 9 rer Jobs Summary view Explorer Connections Support !
" # $ September 15th 2013, 00:00:00.000 to October 13th All jobs * debug 900 Sep 17 2013 Sep 20 2013 Sep 23 2013 Sep 26 2013 Sep 29 2013 Oct 2 2013 Oct 5 2013 Oct 8 2013 Oct 11 2013 0 500000 1000000 1500000 2000000 Infl y timeline : detector Interval: Auto Sep 17 2013 Sep 20 2013 Sep 23 2013 Sep 26 2013 Sep 29 2013 Oct 2 2013 Oct 5 2013 Oct 8 2013 Oct 11 2013 non_zero_count All jobs * debug 900 Sep 17 2013 Sep 20 2013 Sep 23 2013 Sep 26 2013 Sep 29 2013 Oct 2 2013 Oct 5 2013 Oct 8 2013 Oct 11 2013 0 500000 1000000 1500000 2000000 Influ ly timeline : detector Interval: Auto Sep 17 2013 Sep 20 2013 Sep 23 2013 Sep 26 2013 Sep 29 2013 Oct 2 2013 Oct 5 2013 Oct 8 2013 Oct 11 2013 non_zero_count lies 1 3 2 4
ୈिͷΫϩʔζΞοϓ 10 orer Jobs Summary view Explorer Connections Support !
" # $ September 22nd 2013, 00:00:00.000 to September 29th 2 All jobs * l debug _900 Sep 22 09:00 Sep 22 21:00 Sep 23 09:00 Sep 23 21:00 Sep 24 09:00 Sep 24 21:00 Sep 25 09:00 Sep 25 21:00 Sep 26 09:00 Sep 26 21:00 Sep 27 09:00 Sep 27 21:00 Sep 28 09:00 Sep 28 21:00 0 500000 1000000 1500000 2000000 Influ aly timeline by: detector Interval: Auto Sep 22 09:00 Sep 22 21:00 Sep 23 09:00 Sep 23 21:00 Sep 24 09:00 Sep 24 21:00 Sep 25 09:00 Sep 25 21:00 Sep 26 09:00 Sep 26 21:00 Sep 27 09:00 Sep 27 21:00 Sep 28 09:00 Sep 28 21:00 non_zero_count 3 2
1SFMFSUͷςΫϊϩδʔ 11 σʔλʹજΉߦಈϞσϧΛ ࣗಈతʹڭࢣͳֶ͠श ݱࡏͷߦಈ͕༧ଌϞσϧͱ ݦஶʹҟͳΔ߹ʹ௨
Demo
%FNP*5ΦϖϨʔγϣϯ
%FNP*5ΦϖϨʔγϣϯ
%FNP*5ΦϖϨʔγϣϯ
%FNP*5ηΩϡϦςΟ
ϩʔυϚοϓ • ϕʔλ൛Λఏڙத (prelert.com) • Elastic StackͱͷڧݻͳΠϯςάϨʔγϣϯ͕ਐߦத • 2017্ظͷϦϦʔεΛඪ 17