# Anomaly Advisor - beta launch!!!!

**URL:** <https://community.netdata.cloud/t/anomaly-advisor-beta-launch/2717>\
**Category:** General\
**Tags:** announcement\
**Created:** [March 30, 2022, 2:44pm UTC](https://community.netdata.cloud/t/anomaly-advisor-beta-launch/2717 "2022-03-30T14:44:02Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![andrewm4894](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.netdata.cloud/andrewm4894/32/125_2.png) [@andrewm4894](https://community.netdata.cloud/u/andrewm4894)\
**Post date:** [March 30, 2022, 2:44pm UTC](https://community.netdata.cloud/t/anomaly-advisor-beta-launch/2717/1 "2022-03-30T14:44:02Z")

</div>

We are very excited to beta launch our new “Anomaly Advisor” feature for early adopters in the Netdata community. The Anomaly Advisor builds on the recent [ML capabilities](https://learn.netdata.cloud/docs/agent/ml) we have added to the Netdata Agent in order to easily surface potentially anomalous charts and metrics.

## What is the “Anomaly Advisor”?

The Anomaly Advisor gives Netdata Cloud a new “Anomalies” tab where you can quickly scan for periods of time with elevated numbers of anomalous metrics and highlight time periods of interest to surface a sorted list of the most anomalous metrics during the highlighted window.

 ![image](https://canada1.discourse-cdn.com/flex029/uploads/netdata2/original/2X/4/44c27d9ae45b168a45a1cb941032d366df31d99e.png)

 ![image](https://canada1.discourse-cdn.com/flex029/uploads/netdata2/original/2X/a/afea351837fc0a7c626f1532090510a57476c51e.png)

[Here](https://drive.google.com/file/d/1EZrGRcXcqkgFJrUy93QM5E67Lrqo4pP3/view?usp=sharing) is a quick sneak peak video of the feature and [here](https://drive.google.com/file/d/1XFx-H1389bYtVPhVikgLgPVCLXI0mt0r/view?usp=sharing) is a slightly more extended one where we run a little chaos engineering attack on some nodes and see how it plays out in the Anomaly Advisor.

## Getting Started

To enable the Anomaly Advisor you must first enable ML on your nodes via a small config change in `netdata.conf`. Once the anomaly detection models have trained on the agent (with default settings this takes a couple of hours until enough data has been seen to train the models) you will then be able to enable the Anomaly Advisor feature in Netdata Cloud.

### 1. Enable ML on Netdata Agent

To enable ML on you Netdata Agent you just need to edit the `[ml]` section in your `netdata.conf` to look something like below.

Once done, restart Netdata with a command like `sudo systemctl restart netdata` for the config changes to take effect. You can find more info on restarting Netdata [here](https://learn.netdata.cloud/docs/configure/start-stop-restart).

At a minimum you just need to set `enabled = yes` to enable ML with default params. More details can be found in the [Netdata Agent ML docs](https://learn.netdata.cloud/docs/agent/ml#configuration).

```bash
[ml]
    enabled = yes
    # maximum num samples to train = 14400
    # minimum num samples to train = 3600
    # train every = 3600
    # num samples to diff = 1
    # num samples to smooth = 3
    # num samples to lag = 5
    # maximum number of k-means iterations = 1000
    # dimension anomaly score threshold = 0.99
    # host anomaly rate threshold = 0.01000
    # minimum window size = 30.00000
    # maximum window size = 600.00000
    # idle window size = 30.00000
    # window minimum anomaly rate = 0.25000
    # anomaly event min dimension rate threshold = 0.05000
    # hosts to skip from training = !*
    # charts to skip from training = !* netdata.*

```

**Note** : follow [this guide](https://learn.netdata.cloud/guides/step-by-step/step-04) if you are unfamiliar with making configuration changes in Netdata.

### 2. Enable Anomaly Advisor in Netdata Cloud

To enable the Anomaly Advisor feature in Netdata Cloud itself you just need to set a `anomaly_advisor` feature flag to `true` in your browser.

[Here](https://drive.google.com/file/d/1gHA3ovu1Lt5pSdi2ucHYV0vmUIc--Gnp/view?usp=sharing) is a short video showing how to do this.

While on Netdata Cloud, in your browser, if you press F12 you should see the developer tools tab. Press the “Application” tab and under the “Local Storage” section for [https://app.netdata.cloud](https://app.netdata.cloud) you can add a new key & value pair of `anomaly_advisor` & `true`. Once you refresh the page you should now see the new “Anomalies” tab.

 ![image](https://canada1.discourse-cdn.com/flex029/uploads/netdata2/original/2X/9/9d37c3a1a47a8d4b852f495bea713ad5e3f8d479.png)

## Notes

- You can see a detailed list of notes relating to the anomaly detection capabilities of the Netdata Agent [here](https://learn.netdata.cloud/docs/agent/ml#notes).
- If you would like to learn in more detail how the Netdata Agent anomaly detection works please check out the [Netdata Agent ML docs](https://learn.netdata.cloud/docs/agent/ml).
- The default configuration requires at least 3600 seconds (1 hour) of data and will (re)train every 3600 seconds. So after you enable ML on your node, it should take around 2 hours for the first set of models to be trained and anomaly rates to become available for use by the Anomaly Advisor in Netdata Cloud.

## Feedback

We’d love to hear any feedback you have on this thread. This feature is still very much in beta and so may be subject to change. We would love the Netdata community to help us shape this feature more and contribute to its further development in the coming months.

---

<div class="post-metadata">

**Author:** ![andrewm4894](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.netdata.cloud/andrewm4894/32/125_2.png) [@andrewm4894](https://community.netdata.cloud/u/andrewm4894)\
**Post date:** [April 5, 2022, 1:42pm UTC](https://community.netdata.cloud/t/anomaly-advisor-beta-launch/2717/2 "2022-04-05T13:42:36Z")

</div>

For anyone interested in trying this but would like to run it on a parent instead of at the edge below shows some configuration options.

Below assumes 3 child nodes streaming to 1 parent node and illustrates the main ways you might want to configure running ml for the children on the parent, running ml on the children themselves or even a mix of approaches.

![image](https://canada1.discourse-cdn.com/flex029/uploads/netdata2/original/2X/1/1febb775c7eb8448a59324ae757b715e3b7d85a9.png)

```auto
# parent will run ml for itself and child 1,2.
# child 0 will run its own ml at the edge and just stream its ml charts to parent.
# child 1 will run its own ml at the edge, even though parent will also run ml for it, a bit wasteful potentially to run ml in both places but is possible.
# child 2 will not run ml at the edge, it will be run in the parent only.

# parent-ml-ml-stress-0
# run ml on all hosts apart from child-ml-ml-stress-0
[ml]
        enabled = yes
        minimum num samples to train = 900
        train every = 900
        charts to skip from training = !*
        hosts to skip from training = child-ml-ml-stress-0

# child-ml-ml-stress-0
# run ml on child-ml-ml-stress-0 and stream ml charts to parent
[ml]
        enabled = yes
        minimum num samples to train = 900
        train every = 900
        stream anomaly detection charts = yes

# child-ml-ml-stress-1
# run ml on child-ml-ml-stress-1 and stream ml charts to parent
[ml]
        enabled = yes
        minimum num samples to train = 900
        train every = 900
        stream anomaly detection charts = yes

# child-ml-ml-stress-2
# don't run ml on child-ml-ml-stress-2, it will instead run on parent-ml-ml-stress-0
[ml]
        enabled = no

```

---

<div class="post-metadata">

**Author:** ![Tasos\_Katsoulas](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.netdata.cloud/tasos_katsoulas/32/1344_2.png) [@Tasos\_Katsoulas](https://community.netdata.cloud/u/Tasos_Katsoulas)\
**Post date:** [April 6, 2022, 2:26pm UTC](https://community.netdata.cloud/t/anomaly-advisor-beta-launch/2717/3 "2022-04-06T14:26:49Z")

</div>



---

<div class="post-metadata">

**Author:** ![hugo](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.netdata.cloud/hugo/32/3714_2.png) [@hugo](https://community.netdata.cloud/u/hugo)\
**Post date:** [April 7, 2022, 9:23am UTC](https://community.netdata.cloud/t/anomaly-advisor-beta-launch/2717/4 "2022-04-07T09:23:28Z")

</div>

Also a very good hands-on demo done on [Cloud Native Live: Power up your machine learning - Automated anomaly detection](https://www.youtube.com/watch?v=pI-MUupmD64) in case anyone wants to see this in action!

[![](https://canada1.discourse-cdn.com/flex029/uploads/netdata2/original/2X/8/8bac58a481067c3eec9bf843ba41afd09221d34a.jpeg "Cloud Native Live: Power up your machine learning - Automated anomaly detection") ](https://www.youtube.com/watch?v=pI-MUupmD64)

---

<div class="post-metadata">

**Author:** ![andrewm4894](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.netdata.cloud/andrewm4894/32/125_2.png) [@andrewm4894](https://community.netdata.cloud/u/andrewm4894)\
**Post date:** [April 23, 2022, 10:54am UTC](https://community.netdata.cloud/t/anomaly-advisor-beta-launch/2717/5 "2022-04-23T10:54:47Z")

</div>

Another sort of walkthrough video where our CEO is using the Anomaly Advisor to detect a potential bug in his Raspbian OS.

[![](https://canada1.discourse-cdn.com/flex029/uploads/netdata2/original/2X/f/f377e23b65d96a402df9fb1002ca19f2979b9393.jpeg "Walkthrough of Netdata's Machine Learning-based Anomaly Detection debugging a Raspbian issue") ](https://www.youtube.com/watch?v=iMOVorl9BEQ)

---

<div class="post-metadata">

**Author:** ![andrewm4894](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.netdata.cloud/andrewm4894/32/125_2.png) [@andrewm4894](https://community.netdata.cloud/u/andrewm4894)\
**Post date:** [May 5, 2022, 10:33am UTC](https://community.netdata.cloud/t/anomaly-advisor-beta-launch/2717/6 "2022-05-05T10:33:08Z")

</div>

fyi - some official docs here:

> **[Anomaly Advisor | Learn Netdata](https://learn.netdata.cloud/docs/cloud/insights/anomaly-advisor)**
>
> Quickly find anomalous metrics anywhere in your infrastructure.

[https://learn.netdata.cloud/docs/configure/machine-learning](https://learn.netdata.cloud/docs/configure/machine-learning)

---

<div class="post-metadata">

**Author:** ![andrewm4894](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.netdata.cloud/andrewm4894/32/125_2.png) [@andrewm4894](https://community.netdata.cloud/u/andrewm4894)\
**Post date:** [May 18, 2022, 3:36pm UTC](https://community.netdata.cloud/t/anomaly-advisor-beta-launch/2717/7 "2022-05-18T15:36:20Z")

</div>

We’re live!!

> **[Introducing Anomaly Advisor - Unsupervised Anomaly Detection in Netdata -...](https://www.netdata.cloud/blog/introducing-anomaly-advisor-unsupervised-anomaly-detection-in-netdata)**
>
> The Anomaly Advisor builds on earlier work to introduce unsupervised anomaly detection capabilities into the Netdata Agent from v1.32.0 onwards.
