Estimate anomaly detection jobs model memory API

Estimate anomaly detection jobs model memory API

New API reference

For the most up-to-date API details, refer to Machine learning anomaly detection APIs.

Makes an estimation of the memory usage for an anomaly detection job model. It is based on analysis configuration details for the job and cardinality estimates for the fields it references.

Request

POST _ml/anomaly_detectors/_estimate_model_memory

Prerequisites

Requires the manage_ml cluster privilege. This privilege is included in the machine_learning_admin built-in role.

Request body

analysis_config

(Required, object) For a list of the properties that you can specify in the analysis_config component of the body of this API, see analysis_config.

max_bucket_cardinality

(Required*, object) Estimates of the highest cardinality in a single bucket that is observed for influencer fields over the time period that the job analyzes data. To produce a good answer, values must be provided for all influencer fields. Providing values for fields that are not listed as influencers has no effect on the estimation.
*It can be omitted from the request if there are no influencers.

overall_cardinality

(Required*, object) Estimates of the cardinality that is observed for fields over the whole time period that the job analyzes data. To produce a good answer, values must be provided for fields referenced in the by_field_name, over_field_name and partition_field_name of any detectors. Providing values for other fields has no effect on the estimation.
*It can be omitted from the request if no detectors have a by_field_name, over_field_name or partition_field_name.

Examples

  1. resp = client.ml.estimate_model_memory(
  2. analysis_config={
  3. "bucket_span": "5m",
  4. "detectors": [
  5. {
  6. "function": "sum",
  7. "field_name": "bytes",
  8. "by_field_name": "status",
  9. "partition_field_name": "app"
  10. }
  11. ],
  12. "influencers": [
  13. "source_ip",
  14. "dest_ip"
  15. ]
  16. },
  17. overall_cardinality={
  18. "status": 10,
  19. "app": 50
  20. },
  21. max_bucket_cardinality={
  22. "source_ip": 300,
  23. "dest_ip": 30
  24. },
  25. )
  26. print(resp)
  1. response = client.ml.estimate_model_memory(
  2. body: {
  3. analysis_config: {
  4. bucket_span: '5m',
  5. detectors: [
  6. {
  7. function: 'sum',
  8. field_name: 'bytes',
  9. by_field_name: 'status',
  10. partition_field_name: 'app'
  11. }
  12. ],
  13. influencers: [
  14. 'source_ip',
  15. 'dest_ip'
  16. ]
  17. },
  18. overall_cardinality: {
  19. status: 10,
  20. app: 50
  21. },
  22. max_bucket_cardinality: {
  23. source_ip: 300,
  24. dest_ip: 30
  25. }
  26. }
  27. )
  28. puts response
  1. const response = await client.ml.estimateModelMemory({
  2. analysis_config: {
  3. bucket_span: "5m",
  4. detectors: [
  5. {
  6. function: "sum",
  7. field_name: "bytes",
  8. by_field_name: "status",
  9. partition_field_name: "app",
  10. },
  11. ],
  12. influencers: ["source_ip", "dest_ip"],
  13. },
  14. overall_cardinality: {
  15. status: 10,
  16. app: 50,
  17. },
  18. max_bucket_cardinality: {
  19. source_ip: 300,
  20. dest_ip: 30,
  21. },
  22. });
  23. console.log(response);
  1. POST _ml/anomaly_detectors/_estimate_model_memory
  2. {
  3. "analysis_config": {
  4. "bucket_span": "5m",
  5. "detectors": [
  6. {
  7. "function": "sum",
  8. "field_name": "bytes",
  9. "by_field_name": "status",
  10. "partition_field_name": "app"
  11. }
  12. ],
  13. "influencers": [ "source_ip", "dest_ip" ]
  14. },
  15. "overall_cardinality": {
  16. "status": 10,
  17. "app": 50
  18. },
  19. "max_bucket_cardinality": {
  20. "source_ip": 300,
  21. "dest_ip": 30
  22. }
  23. }

The estimate returns the following result:

  1. {
  2. "model_memory_estimate": "21mb"
  3. }