The anomaly detection service, as scripts see it. The division of labour is deliberate. This side owns the statistics, the alarm lifecycle and persistence, because those want unit tests and a real numerics library. The app side owns the detector definitions, the metric queries and the schedule, because that is where index queries and app providers already live. So a scan reads: build a detector from its definition, fetch its series from its index query, hand both to the scan method, then fire whatever the returned transition asks for.

Group: Managers


Properties

PropertyReturnsDescription
alarmServiceAnomalyAlarmServiceThe alarm lifecycle, for a caller that wants to advance state without going through the scan method.
storeAnomalyStoreThe store holding this tenant's detector overrides, custom detectors and alarm state.

Methods

getStore() · getAlarmService() · newDetectorBuilder() · newThresholdBuilder() · newTripBuilder() · newSeriesBuilder() · scan(String detectorName, AnomalyDetector detector, List<AnomalyDataPoint> series, AnomalyTripConfig trip, Date now) · backtest(AnomalyDetector detector, List<AnomalyDataPoint> series, Date now) · resetState(String detectorName)

getStore()

Returns: AnomalyStore

The store holding this tenant's detector overrides, custom detectors and alarm state.

getAlarmService()

Returns: AnomalyAlarmService

The alarm lifecycle, for a caller that wants to advance state without going through the scan method.

newDetectorBuilder()

Returns: Builder

Starts building a new detector, pre-filled with defaults suitable for a daily metric.

newThresholdBuilder()

Returns: Builder

Starts building the gates a bucket must fail every one of to be called anomalous.

newTripBuilder()

Returns: Builder

Starts building the hysteresis and re-notification settings that control when an incident opens, closes and repeats.

newSeriesBuilder()

Returns: SeriesBuilder

Starts collecting a metric time series a bucket at a time.

scan(String detectorName, AnomalyDetector detector, List<AnomalyDataPoint> series, AnomalyTripConfig trip, Date now)

Returns: AnomalyScanResult

Run one detector: evaluate its newest closed bucket, advance its alarm state, and persist the result. Safe to call more often than buckets close, which is the normal case - the scheduler runs hourly and most detectors are daily. A bucket already accounted for advances nothing, fires nothing and writes nothing, so an over-eager schedule costs a query and no more.

ParameterDescription
detectorNamethe detector's name, used as the persistence key. Must be a valid name
detectorthe configured detector. Must not be null
seriesthe metric time series, which may include a bucket still filling. Must not be null
tripthe hysteresis and re-notification settings. Must not be null
nowthe current instant. Must not be null

backtest(AnomalyDetector detector, List<AnomalyDataPoint> series, Date now)

Returns: List<AnomalyResult>

Replay a detector over a series, without touching stored state. This is how a detector is judged before it is trusted, and how a brand new detector's screen gets something to show on day one. Nothing is persisted and no events are implied.

ParameterDescription
detectorthe configured detector. Must not be null
seriesthe metric time series. Must not be null
nowthe instant to judge bucket closure against. Must not be null

resetState(String detectorName)

Returns: boolean

Discard a detector's alarm state and history, so it starts again from cold. For use after retuning, when the recorded history describes a detector that no longer exists.

ParameterDescription
detectorNamethe detector's name. Must be a valid name
To get full access to the Kademi Hub existing customers can login here, or new customers can register here.