The anomaly detection service, as scripts see it. The division of labour is deliberate. This side owns the statistics, the alarm lifecycle and persistence, because those want unit tests and a real numerics library. The app side owns the detector definitions, the metric queries and the schedule, because that is where index queries and app providers already live. So a scan reads: build a detector from its definition, fetch its series from its index query, hand both to the scan method, then fire whatever the returned transition asks for.
Group: Managers
Properties
| Property | Returns | Description |
|---|---|---|
| alarmService | AnomalyAlarmService | The alarm lifecycle, for a caller that wants to advance state without going through the scan method. |
| store | AnomalyStore | The store holding this tenant's detector overrides, custom detectors and alarm state. |
Methods
getStore() · getAlarmService() · newDetectorBuilder() · newThresholdBuilder() · newTripBuilder() · newSeriesBuilder() · scan(String detectorName, AnomalyDetector detector, List<AnomalyDataPoint> series, AnomalyTripConfig trip, Date now) · backtest(AnomalyDetector detector, List<AnomalyDataPoint> series, Date now) · resetState(String detectorName)
getStore()
Returns: AnomalyStore
The store holding this tenant's detector overrides, custom detectors and alarm state.
getAlarmService()
Returns: AnomalyAlarmService
The alarm lifecycle, for a caller that wants to advance state without going through the scan method.
newDetectorBuilder()
Returns: Builder
Starts building a new detector, pre-filled with defaults suitable for a daily metric.
newThresholdBuilder()
Returns: Builder
Starts building the gates a bucket must fail every one of to be called anomalous.
newTripBuilder()
Returns: Builder
Starts building the hysteresis and re-notification settings that control when an incident opens, closes and repeats.
newSeriesBuilder()
Returns: SeriesBuilder
Starts collecting a metric time series a bucket at a time.
scan(String detectorName, AnomalyDetector detector, List<AnomalyDataPoint> series, AnomalyTripConfig trip, Date now)
Returns: AnomalyScanResult
Run one detector: evaluate its newest closed bucket, advance its alarm state, and persist the result. Safe to call more often than buckets close, which is the normal case - the scheduler runs hourly and most detectors are daily. A bucket already accounted for advances nothing, fires nothing and writes nothing, so an over-eager schedule costs a query and no more.
| Parameter | Description |
|---|---|
detectorName | the detector's name, used as the persistence key. Must be a valid name |
detector | the configured detector. Must not be null |
series | the metric time series, which may include a bucket still filling. Must not be null |
trip | the hysteresis and re-notification settings. Must not be null |
now | the current instant. Must not be null |
backtest(AnomalyDetector detector, List<AnomalyDataPoint> series, Date now)
Returns: List<AnomalyResult>
Replay a detector over a series, without touching stored state. This is how a detector is judged before it is trusted, and how a brand new detector's screen gets something to show on day one. Nothing is persisted and no events are implied.
| Parameter | Description |
|---|---|
detector | the configured detector. Must not be null |
series | the metric time series. Must not be null |
now | the instant to judge bucket closure against. Must not be null |
resetState(String detectorName)
Returns: boolean
Discard a detector's alarm state and history, so it starts again from cold. For use after retuning, when the recorded history describes a detector that no longer exists.
| Parameter | Description |
|---|---|
detectorName | the detector's name. Must be a valid name |