Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Anomaly Detection with the Elastic Stack
Search
Kosho Owa
December 15, 2016
Technology
1
1.8k
Anomaly Detection with the Elastic Stack
Prelert: Elastic Stackを利用した異常検知
Elastic{ON} Tour Tokyo 2016
Kosho Owa
December 15, 2016
Tweet
Share
More Decks by Kosho Owa
See All by Kosho Owa
Introducing Machine Learning for the Elastic Stack
kosho
2
12k
Elastic Stack X-Pack 5.0 for IT Security Workshop
kosho
1
310
Elastic Stack X-Pack 5.0 for IT Ops Workshop
kosho
0
330
[Developers Summit 2017] Anomaly Detection with the Elastic Stack
kosho
1
710
Getting Started with Elastic Cloud and Beats for Log Analytics
kosho
0
100
Elastic{ON} Seminar Tokyo 2016 Product Update
kosho
0
170
Introducing Elastic Cloud
kosho
0
76
Gearing Up for Elastic Stack, X-Pack 5.0 Releases
kosho
0
150
Elastic Stack Hands-on Workshop (EN)
kosho
1
160
Other Decks in Technology
See All in Technology
品質視点から考える組織デザイン/Organizational Design from Quality
mii3king
0
190
AI駆動開発に向けた新しいエンジニアマインドセット
kazue
0
340
ガチな登山用デバイスからこんにちは
halka
1
230
下手な強制、ダメ!絶対! 「ガードレール」を「檻」にさせない"ガバナンス"の取り方とは?
tsukaman
2
420
AIエージェント開発用SDKとローカルLLMをLINE Botと組み合わせてみた / LINEを使ったLT大会 #14
you
PRO
0
100
roppongirb_20250911
igaiga
1
200
Flutterでキャッチしないエラーはどこに行く
taiju59
0
220
Snowflakeの生成AI機能を活用したデータ分析アプリの作成 〜Cortex AnalystとCortex Searchの活用とStreamlitアプリでの利用〜
nayuts
1
460
20250903_1つのAWSアカウントに複数システムがある環境におけるアクセス制御をABACで実現.pdf
yhana
3
540
未経験者・初心者に贈る!40分でわかるAndroidアプリ開発の今と大事なポイント
operando
4
350
ChatGPTとPlantUML/Mermaidによるソフトウェア設計
gowhich501
1
130
【初心者向け】ローカルLLMの色々な動かし方まとめ
aratako
7
3.4k
Featured
See All Featured
[RailsConf 2023] Rails as a piece of cake
palkan
57
5.8k
How to train your dragon (web standard)
notwaldorf
96
6.2k
Responsive Adventures: Dirty Tricks From The Dark Corners of Front-End
smashingmag
252
21k
What’s in a name? Adding method to the madness
productmarketing
PRO
23
3.7k
What's in a price? How to price your products and services
michaelherold
246
12k
A Tale of Four Properties
chriscoyier
160
23k
Optimising Largest Contentful Paint
csswizardry
37
3.4k
I Don’t Have Time: Getting Over the Fear to Launch Your Podcast
jcasabona
33
2.4k
Into the Great Unknown - MozCon
thekraken
40
2k
Imperfection Machines: The Place of Print at Facebook
scottboms
268
13k
Site-Speed That Sticks
csswizardry
10
810
Creating an realtime collaboration tool: Agile Flush - .NET Oxford
marcduiker
31
2.2k
Transcript
Prelert: Elastic StackΛར༻ͨ͠ҟৗݕ େྠ ߂ৄ | Kosho Owa Solutions Architect,
Elastic
*5ΦϖϨʔγϣϯ • ࣗͷγεςϜਖ਼ৗʹՔಇ͍ͯ͠Δ? • ͲͷΑ͏ʹᮢΛஅ͢Δ? • ͕ൃੜͨ࣌͠ʹɺͲͷΑ͏ʹݪҼΛݟ͚ͭΔ? 2
*5ηΩϡϦςΟ • ϚϧΣΞʹ৵ೖ͞Ε͍ͯΔγεςϜແ͍͔? • ϚϧΣΞ͕ͲͷΑ͏ʹײછΛ͔͛ͨ? • જࡏతʹڴҖͱͳΔ৫෦ͷϢʔβʔ୭͔? 3
ͦͷଞ • ͲͷΑ͏ʹɺଟ͘ͷछྨͷ࣌ܥྻσʔλͱ͖߹͏͔? • ਖ਼ৗʹՔಇ͍ͯ͠Δ? • Ͳͷަ௨ࣄނ͕࠷ौΛҾ͖ى͍ͯ͜͠Δ͔? 4
σʔλ͔Β༗ҙٛͳใΛݟ͚ͭΔํ๏ 5 Search Aggregations Visualization Machine Learning
t_900 - Dashboard New Add Save Open Share Options !
~ 3 years ago to ~ 3 years ago 900 - Actual 2013-09-18 00:00 2013-09-21 00:00 2013-09-24 00:00 2013-09-27 00:00 2013-09-30 00:00 2013-10-03 00:00 2013-10-06 00:00 2013-10-09 00:00 2013-10-12 00:00 0 1000000 2000000 3000000 4000000 5000000 6000000 7000000 8000000 Actual 900 - Moving Average 6000000 7000000 8000000 Moving Average Actual Anomaly " ҟৗݕͷνϟϨϯδ 6 1 3 2 4 2 2 2 2 week
ҠಈฏۉʹΑΔҟৗݕ 7 t_900 - Dashboard New Add Save Open Share
Options ! ~ 3 years ago to ~ 3 years ago 900 - Moving Average 2013-09-18 00:00 2013-09-21 00:00 2013-09-24 00:00 2013-09-27 00:00 2013-09-30 00:00 2013-10-03 00:00 2013-10-06 00:00 2013-10-09 00:00 2013-10-12 00:00 0 1000000 2000000 3000000 4000000 5000000 6000000 7000000 8000000 Moving Average Actual Anomaly 900 - Holt-Winters 8000000 9000000 HoltWinters Actual Anomaly "
)PMU8JOUFSTʹΑΔҟৗݕ 8 _900 - Dashboard New Add Save Open Share
Options ! ~ 3 years ago to ~ 3 years ago 900 - Holt-Winters 2013-09-18 00:00 2013-09-21 00:00 2013-09-24 00:00 2013-09-27 00:00 2013-09-30 00:00 2013-10-03 00:00 2013-10-06 00:00 2013-10-09 00:00 2013-10-12 00:00 0 1000000 2000000 3000000 4000000 5000000 6000000 7000000 8000000 9000000 HoltWinters Actual Anomaly ly timeline : detector Interval: Auto Sep 17 2013 Sep 19 2013 Sep 21 2013 Sep 23 2013 Sep 25 2013 Sep 27 2013 Sep 29 2013 Oct 1 2013 Oct 3 2013 Oct 5 2013 Oct 7 2013 Oct 9 2013 Oct 11 2013 non_zero_count "
1SFMFSUʹΑΔҟৗݕ 9 rer Jobs Summary view Explorer Connections Support !
" # $ September 15th 2013, 00:00:00.000 to October 13th All jobs * debug 900 Sep 17 2013 Sep 20 2013 Sep 23 2013 Sep 26 2013 Sep 29 2013 Oct 2 2013 Oct 5 2013 Oct 8 2013 Oct 11 2013 0 500000 1000000 1500000 2000000 Infl y timeline : detector Interval: Auto Sep 17 2013 Sep 20 2013 Sep 23 2013 Sep 26 2013 Sep 29 2013 Oct 2 2013 Oct 5 2013 Oct 8 2013 Oct 11 2013 non_zero_count All jobs * debug 900 Sep 17 2013 Sep 20 2013 Sep 23 2013 Sep 26 2013 Sep 29 2013 Oct 2 2013 Oct 5 2013 Oct 8 2013 Oct 11 2013 0 500000 1000000 1500000 2000000 Influ ly timeline : detector Interval: Auto Sep 17 2013 Sep 20 2013 Sep 23 2013 Sep 26 2013 Sep 29 2013 Oct 2 2013 Oct 5 2013 Oct 8 2013 Oct 11 2013 non_zero_count lies 1 3 2 4
ୈिͷΫϩʔζΞοϓ 10 orer Jobs Summary view Explorer Connections Support !
" # $ September 22nd 2013, 00:00:00.000 to September 29th 2 All jobs * l debug _900 Sep 22 09:00 Sep 22 21:00 Sep 23 09:00 Sep 23 21:00 Sep 24 09:00 Sep 24 21:00 Sep 25 09:00 Sep 25 21:00 Sep 26 09:00 Sep 26 21:00 Sep 27 09:00 Sep 27 21:00 Sep 28 09:00 Sep 28 21:00 0 500000 1000000 1500000 2000000 Influ aly timeline by: detector Interval: Auto Sep 22 09:00 Sep 22 21:00 Sep 23 09:00 Sep 23 21:00 Sep 24 09:00 Sep 24 21:00 Sep 25 09:00 Sep 25 21:00 Sep 26 09:00 Sep 26 21:00 Sep 27 09:00 Sep 27 21:00 Sep 28 09:00 Sep 28 21:00 non_zero_count 3 2
1SFMFSUͷςΫϊϩδʔ 11 σʔλʹજΉߦಈϞσϧΛ ࣗಈతʹڭࢣͳֶ͠श ݱࡏͷߦಈ͕༧ଌϞσϧͱ ݦஶʹҟͳΔ߹ʹ௨
Demo
%FNP*5ΦϖϨʔγϣϯ
%FNP*5ΦϖϨʔγϣϯ
%FNP*5ΦϖϨʔγϣϯ
%FNP*5ηΩϡϦςΟ
ϩʔυϚοϓ • ϕʔλ൛Λఏڙத (prelert.com) • Elastic StackͱͷڧݻͳΠϯςάϨʔγϣϯ͕ਐߦத • 2017্ظͷϦϦʔεΛඪ 17