What the detector concluded about one bucket, and why. Every field an alert message or an admin screen needs is here, because an alert nobody can explain is an alert nobody acts on. In particular the percentage of normal is the number to lead with: the score decides, the percentage explains.
Properties
| Property | Returns | Description |
|---|---|---|
| absChange | double | How far the observed value sits from expected, in absolute terms. |
| anomalous | boolean | Whether this bucket failed every configured gate and so counts as anomalous. |
| baselineSamples | int | How many comparable buckets the baseline was drawn from. |
| bucketDate | Date | The first instant of the bucket that was evaluated. |
| direction | AnomalyDirection | Which side of normal the observation fell on. |
| directionName | String | The direction as a string, for script and for persistence. |
| expected | double | The median of the comparable buckets - what the value should have been. |
| insufficientBaseline | boolean | Whether there was not enough comparable history to judge this bucket. |
| observed | double | The value actually aggregated for the bucket. |
| percentOfNormal | Double | The observation as a percentage of normal - 50 means half the usual, 200 means double. This is the figure to lead an alert with. |
| scale | double | The spread of the comparable buckets, as a median absolute deviation scaled to be comparable with a standard deviation. Exposed for diagnosis: a detector that never fires usually has a larger scale than whoever configured it expected. |
| score | double | The modified z-score: how many robust deviations the observation sits from the median, always positive. Capped at a fixed score cap so that a perfectly flat baseline yields a finite, serialisable number rather than an infinity. |
| status | Status | The verdict reached for this bucket. |
| statusName | String | The verdict as a string, for script and for persistence. |
| summary | String | One sentence saying what happened, in the terms an administrator thinks in. Suitable for an alert body, a log line or a table cell. |
Methods
getBucketDate() · getObserved() · getExpected() · getScale() · getScore() · getPercentOfNormal() · getAbsChange() · getBaselineSamples() · getStatus() · getStatusName() · getDirection() · getDirectionName() · isAnomalous() · isInsufficientBaseline() · getSummary()
getBucketDate()
Returns: Date
The first instant of the bucket that was evaluated.
getObserved()
Returns: double
The value actually aggregated for the bucket.
getExpected()
Returns: double
The median of the comparable buckets - what the value should have been.
getScale()
Returns: double
The spread of the comparable buckets, as a median absolute deviation scaled to be comparable with a standard deviation. Exposed for diagnosis: a detector that never fires usually has a larger scale than whoever configured it expected.
getScore()
Returns: double
The modified z-score: how many robust deviations the observation sits from the median, always positive. Capped at a fixed score cap so that a perfectly flat baseline yields a finite, serialisable number rather than an infinity.
getPercentOfNormal()
Returns: Double
The observation as a percentage of normal - 50 means half the usual, 200 means double. This is the figure to lead an alert with.
getAbsChange()
Returns: double
How far the observed value sits from expected, in absolute terms.
getBaselineSamples()
Returns: int
How many comparable buckets the baseline was drawn from.
getStatus()
Returns: Status
The verdict reached for this bucket.
getStatusName()
Returns: String
The verdict as a string, for script and for persistence.
getDirection()
Returns: AnomalyDirection
Which side of normal the observation fell on.
getDirectionName()
Returns: String
The direction as a string, for script and for persistence.
isAnomalous()
Returns: boolean
Whether this bucket failed every configured gate and so counts as anomalous.
isInsufficientBaseline()
Returns: boolean
Whether there was not enough comparable history to judge this bucket.
getSummary()
Returns: String
One sentence saying what happened, in the terms an administrator thinks in. Suitable for an alert body, a log line or a table cell.