Skip to content

Conversation

kosabogi
Copy link
Contributor

@kosabogi kosabogi commented Apr 2, 2025

This PR updates the anomaly detection alerting documentation to clarify that email alerts include only the top three anomalous records or influencers.

Related issue: https://github.com/elastic/search-docs-team/issues/277

@kosabogi kosabogi added >docs General docs changes Team:Docs Meta label for docs team auto-backport Automatically create backport pull requests when merged v8.16.0 v8.17.0 v8.18.0 labels Apr 2, 2025
Copy link
Contributor

github-actions bot commented Apr 2, 2025

Documentation preview:

@kosabogi kosabogi requested a review from szabosteve April 2, 2025 09:13
@kosabogi kosabogi marked this pull request as ready for review April 2, 2025 09:15
@elasticsearchmachine
Copy link
Collaborator

Pinging @elastic/es-docs (Team:Docs)

@kosabogi kosabogi requested a review from darnautov April 3, 2025 10:14
alert status changes, or at a custom action interval). For {anomaly-detect}
alert status changes, or at a custom action interval).

When you use an email action with an {anomaly-detect} rule, the alert includes only the top three anomalous records or influencers detected during the check interval. This behavior ensures that the alert remains concise by highlighting the most significant anomalies based on their scores.
Copy link
Contributor

@darnautov darnautov Apr 3, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It is not specifically about email actions but rather about the overall alert context sent to any connector, as well as the document stored in the alert-as-data index.

I believe we should simply mention that topRecords and topInfluencers are limited to 3 documents.

image

@kosabogi kosabogi requested a review from darnautov April 4, 2025 05:56
Copy link
Contributor

@szabosteve szabosteve left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM unless @darnautov thinks otherwise. :)

Copy link
Contributor

@darnautov darnautov left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@kosabogi kosabogi merged commit c4e9f0b into elastic:8.x Apr 8, 2025
5 checks passed
kosabogi added a commit to kosabogi/elasticsearch that referenced this pull request Apr 8, 2025
* Adds note on anomaly detection alert behaviour

* Fixes attribute

* Relocating the addition

* Fixes based on feedback
kosabogi added a commit to kosabogi/elasticsearch that referenced this pull request Apr 8, 2025
* Adds note on anomaly detection alert behaviour

* Fixes attribute

* Relocating the addition

* Fixes based on feedback
@elasticsearchmachine
Copy link
Collaborator

💚 Backport successful

Status Branch Result
8.16
8.17
8.18

kosabogi added a commit to kosabogi/elasticsearch that referenced this pull request Apr 8, 2025
* Adds note on anomaly detection alert behaviour

* Fixes attribute

* Relocating the addition

* Fixes based on feedback
elasticsearchmachine pushed a commit that referenced this pull request Apr 8, 2025
* Adds note on anomaly detection alert behaviour

* Fixes attribute

* Relocating the addition

* Fixes based on feedback
elasticsearchmachine pushed a commit that referenced this pull request Apr 8, 2025
* Adds note on anomaly detection alert behaviour

* Fixes attribute

* Relocating the addition

* Fixes based on feedback
elasticsearchmachine pushed a commit that referenced this pull request Apr 8, 2025
* Adds note on anomaly detection alert behaviour

* Fixes attribute

* Relocating the addition

* Fixes based on feedback
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

auto-backport Automatically create backport pull requests when merged >docs General docs changes Team:Docs Meta label for docs team v8.16.0 v8.17.0 v8.18.0 v8.19.0

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants