Revert model snapshots API

Revert model snapshots API

Reverts to a specific snapshot.

Request

POST _ml/anomaly_detectors/<job_id>/model_snapshots/<snapshot_id>/_revert

Prerequisites

  • Before you revert to a saved snapshot, you must close the job.
  • Requires the manage_ml cluster privilege. This privilege is included in the machine_learning_admin built-in role.

Description

The machine learning features reacts quickly to anomalous input, learning new behaviors in data. Highly anomalous input increases the variance in the models whilst the system learns whether this is a new step-change in behavior or a one-off event. In the case where this anomalous input is known to be a one-off, then it might be appropriate to reset the model state to a time before this event. For example, you might consider reverting to a saved snapshot after Black Friday or a critical system failure.

Reverting to a snapshot does not change the data_counts values of the anomaly detection job, these values are not reverted to the earlier state.

Path parameters

<job_id>

(Required, string) Identifier for the anomaly detection job.

<snapshot_id>

(Required, string) A numerical character string that uniquely identifies the model snapshot.

You can specify empty as the <snapshot_id>. Reverting to the empty snapshot means the anomaly detection job starts learning a new model from scratch when it is started.

Query parameters

delete_intervening_results

(Optional, Boolean) If true, deletes the results in the time period between the latest results and the time of the reverted snapshot. It also resets the model to accept records for this time period. The default value is false.

If you choose not to delete intervening results when reverting a snapshot, the job will not accept input data that is older than the current time. If you want to resend data, then delete the intervening results.

Request body

You can also specify the delete_intervening_results query parameter in the request body.

Examples

  1. POST _ml/anomaly_detectors/low_request_rate/model_snapshots/1637092688/_revert
  2. {
  3. "delete_intervening_results": true
  4. }

When the operation is complete, you receive the following results:

  1. {
  2. "model" : {
  3. "job_id" : "low_request_rate",
  4. "min_version" : "7.11.0",
  5. "timestamp" : 1637092688000,
  6. "description" : "State persisted due to job close at 2021-11-16T19:58:08+0000",
  7. "snapshot_id" : "1637092688",
  8. "snapshot_doc_count" : 1,
  9. "model_size_stats" : {
  10. "job_id" : "low_request_rate",
  11. "result_type" : "model_size_stats",
  12. "model_bytes" : 45200,
  13. "peak_model_bytes" : 101552,
  14. "model_bytes_exceeded" : 0,
  15. "model_bytes_memory_limit" : 11534336,
  16. "total_by_field_count" : 3,
  17. "total_over_field_count" : 0,
  18. "total_partition_field_count" : 2,
  19. "bucket_allocation_failures_count" : 0,
  20. "memory_status" : "ok",
  21. "assignment_memory_basis" : "current_model_bytes",
  22. "categorized_doc_count" : 0,
  23. "total_category_count" : 0,
  24. "frequent_category_count" : 0,
  25. "rare_category_count" : 0,
  26. "dead_category_count" : 0,
  27. "failed_category_count" : 0,
  28. "categorization_status" : "ok",
  29. "log_time" : 1637092688530,
  30. "timestamp" : 1641495600000
  31. },
  32. "latest_record_time_stamp" : 1641502169000,
  33. "latest_result_time_stamp" : 1641495600000,
  34. "retain" : false
  35. }
  36. }

For a description of these properties, see the get model snapshots API.