A detector's persisted position: what state it is in, how it got there, and what it has seen. Two separate records of the past are kept, because they answer different questions and have very different sizes. The recent buckets list is a bounded window of every evaluation, which is what the sparkline on the admin screen draws. The anomalies list is every anomalous bucket within the retention period, which is what thresholds get tuned against. Keeping all of both for an hourly detector would mean parsing several thousand entries on every scan for no benefit.


Properties

PropertyReturnsDescription
anomaliesList<AnomalyHistoryEntry>Every anomalous bucket still within the retention period, oldest first.
anomalyCountintHow many anomalies are on record within the retention period.
clearedDateDateWhen the detector's most recently open incident was judged recovered.
consecutiveAnomalousintHow many anomalous buckets have arrived in a row, the counter hysteresis is judged against.
consecutiveCleanintHow many normal buckets have arrived in a row since the last anomalous one, used to decide when an open incident recovers.
detectorNameStringName of the detector this state belongs to, and the key it is persisted under.
firstDetectedDateWhen the current run of abnormality began.
inAlarmbooleanWhether an incident is currently open for this detector.
lastDetectedDateThe most recent bucket that was judged anomalous.
lastEvaluatedBucketDateThe newest bucket already accounted for. The scheduler runs far more often than a daily bucket closes, so without this a single bad day would be counted as two dozen consecutive anomalous buckets and would trip any hysteresis immediately.
lastNotifiedDateWhen an alarm event was last fired for the open incident. This is what the re-notification window is measured from, and it is cleared when the incident closes so the next one notifies at once.
lastScannedDateWhen this detector's scheduler last ran, regardless of whether it found a new bucket to evaluate.
latestAnomalyHistoryEntryThe most recent evaluation of any kind, anomalous or not.
recentBucketsList<AnomalyHistoryEntry>A bounded window of every evaluated bucket, oldest first, for drawing the recent trend.
stateAlarmStateWhere the detector currently stands in the alarm lifecycle.
stateNameStringThe current state as a string, for script and templates that cannot work with the enum directly.

Methods

getDetectorName() · getState() · getStateName() · isInAlarm() · getConsecutiveAnomalous() · getConsecutiveClean() · getFirstDetected() · getLastDetected() · getClearedDate() · getLastNotified() · getLastEvaluatedBucket() · getLastScanned() · getLatest() · getRecentBuckets() · getAnomalies() · getAnomalyCount()

getDetectorName()

Returns: String

Name of the detector this state belongs to, and the key it is persisted under.

getState()

Returns: AlarmState

Where the detector currently stands in the alarm lifecycle.

getStateName()

Returns: String

The current state as a string, for script and templates that cannot work with the enum directly.

isInAlarm()

Returns: boolean

Whether an incident is currently open for this detector.

getConsecutiveAnomalous()

Returns: int

How many anomalous buckets have arrived in a row, the counter hysteresis is judged against.

getConsecutiveClean()

Returns: int

How many normal buckets have arrived in a row since the last anomalous one, used to decide when an open incident recovers.

getFirstDetected()

Returns: Date

When the current run of abnormality began.

getLastDetected()

Returns: Date

The most recent bucket that was judged anomalous.

getClearedDate()

Returns: Date

When the detector's most recently open incident was judged recovered.

getLastNotified()

Returns: Date

When an alarm event was last fired for the open incident. This is what the re-notification window is measured from, and it is cleared when the incident closes so the next one notifies at once.

getLastEvaluatedBucket()

Returns: Date

The newest bucket already accounted for. The scheduler runs far more often than a daily bucket closes, so without this a single bad day would be counted as two dozen consecutive anomalous buckets and would trip any hysteresis immediately.

getLastScanned()

Returns: Date

When this detector's scheduler last ran, regardless of whether it found a new bucket to evaluate.

getLatest()

Returns: AnomalyHistoryEntry

The most recent evaluation of any kind, anomalous or not.

getRecentBuckets()

Returns: List<AnomalyHistoryEntry>

A bounded window of every evaluated bucket, oldest first, for drawing the recent trend.

getAnomalies()

Returns: List<AnomalyHistoryEntry>

Every anomalous bucket still within the retention period, oldest first.

getAnomalyCount()

Returns: int

How many anomalies are on record within the retention period.

To get full access to the Kademi Hub existing customers can login here, or new customers can register here.