When a deviation from normal is worth telling somebody about. Three independent gates, and a bucket must fail all of them to be called anomalous. That conjunction is the whole point: any one of them alone produces an unusable stream of false positives on real data. The score gate measures how far outside the historical spread the value sits, but on a very stable series a trivial wobble also scores highly. The percent band measures how far off normal in proportional terms, which is the number an admin can actually reason about and filters the stable-series case. The minimum absolute change gate is the practical false-positive killer - without it a quiet account going from one order to three trips both gates above, every time.
Properties
| Property | Returns | Description |
|---|---|---|
| direction | AnomalyDirection | Which side or sides of normal this detector cares about. |
| minAbsChange | double | The minimum absolute change gate. |
| percentHigh | Double | The high side of the percent-of-normal gate. |
| percentLow | Double | The low side of the percent-of-normal gate. |
| score | double | The modified z-score gate. |
Methods
getScore()
Returns: double
The modified z-score gate.
getPercentLow()
Returns: Double
The low side of the percent-of-normal gate.
getPercentHigh()
Returns: Double
The high side of the percent-of-normal gate.
getMinAbsChange()
Returns: double
The minimum absolute change gate.
getDirection()
Returns: AnomalyDirection
Which side or sides of normal this detector cares about.