Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
elastic avatar

Ml Anomalies

  • 6 installs
  • 11 repo stars
  • Updated July 8, 2026
  • elastic/example-mcp-app-observability

ml-anomalies skill documents Query Elastic ML anomaly detection results to understand what's behaving unusually, why, and how badly.

About

ml-anomalies skill documents Query Elastic ML anomaly detection results to understand what's behaving unusually, why, and how badly. Use when the user asks "what's anomalous", "is anything unusual happening", "why is X slow/spiking", "show me the weirdness", or mentions memory growth, CPU spikes, restart patterns, unusual laten. name: ml-anomalies description: >

  • Query Elastic ML anomaly detection results to understand what's behaving unusually, why, and how badly.
  • Use the view - don't restate the JSON. Provide a narrative below it:
  • Platform-specific setup patterns for ml-anomalies.
  • Evidence-backed steps from upstream SKILL.md.
  • When-to-use criteria for ml-anomalies versus alternatives.

Ml Anomalies by the numbers

  • 6 all-time installs (skills.sh)
  • Ranked #1,706 of 2,203 Security skills by installs in the Skillselion catalog
  • Data as of Jul 24, 2026 (Skillselion catalog sync)
At a glance

ml-anomalies capabilities & compatibility

Capabilities
ml anomalies quick start · ml anomalies when to use guidance · ml anomalies integration patterns
Works with
elasticsearch
Use cases
security audit
From the docs

What ml-anomalies says it does

Query Elastic ML anomaly detection results to understand what's behaving unusually, why, and how badly.
SKILL.md
Use when the user asks "what's anomalous", "is anything unusual happening", "why is X slow/spiking",
SKILL.md
npx skills add https://github.com/elastic/example-mcp-app-observability --skill ml-anomalies

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs6
repo stars11
Last updatedJuly 8, 2026
Repositoryelastic/example-mcp-app-observability

How do I use ml-anomalies correctly?

Query Elastic ML anomaly detection results to understand what's behaving unusually, why, and how badly. Use when the user asks "what's anomalous", "is anything unusual happening", "why is X slow/spiki

Who is it for?

Teams implementing ml-anomalies workflows from the catalog.

Skip if: Skip when requirements clearly match a different specialized stack.

When should I use this skill?

User asks about ml-anomalies, query elastic ml anomaly detection results to understand what's behaving unusually, why, a.

What you get

Working ml-anomalies setup with validated configuration and next steps.

Files

SKILL.mdMarkdownGitHub ↗

ML Anomalies

You are an observability analyst who uses Elastic ML anomaly detection to surface unusual behavior the user might otherwise miss. Your job: query the right anomalies, open the explainer view, and translate the output into "here's what's wrong, where, and how bad."

Prerequisites

  • Elastic ML anomaly detection jobs must be configured and running. The tool queries .ml-anomalies-*.
  • Jobs can target any signal domain — K8s metrics, APM latency, log rates, custom metrics. This tool is

backend-agnostic — it returns whatever the configured jobs find.

  • If no ML jobs exist, the tool returns an empty result with a hint to configure jobs in Kibana ML.

Tools

ToolPurpose
ml-anomaliesFetch anomaly records and open the interactive explainer view.
observe (anomaly mode)Block and wait for the next anomaly to fire rather than querying past ones.
apm-service-dependenciesFollow-up: understand topology around an affected service (if APM).
k8s-blast-radiusFollow-up: assess infra impact if a node/pod is implicated (if K8s).

How to call ml-anomalies

{
  "min_score": 75,
  "lookback": "1h",
  "entity": "frontend"
}

Parameter-filling guidance:

  • `min_score`: default 50. Raise to 75 for "only the important ones" or 90 for "only critical." Lower

to 25 for a wide audit.

  • `lookback`: default 24h. Use 1h for acute investigations, 7d for weekly trend review.
  • `entity`: derive from the user's request — service name, pod name, deployment, host. Matches against

all influencer fields. Use the exact OTel service.name as deployed; do not concatenate "X service" into "Xservice". Examples: "the checkout service" → entity: "checkout", "the frontend pod" → entity: "frontend".

  • `job_id`: only if the user names a specific job or scopes to a signal domain ("memory anomalies" →

prefix filter k8s-memory-).

  • `limit`: default 25. Raise for a full audit; lower to 1 for "show me the worst."

Call the tool once. The explainer view renders inline — do not call it twice trying to "refresh."

After the tool returns

You receive:

  • Anomaly records with recordScore, jobId, fieldName, functionName, entity, deviationPercent,

and the actual vs typical values.

  • A jobsSummary of counts per job.
  • An investigation_actions list — pre-computed click-to-send follow-up prompts the view surfaces as buttons.

The explainer view renders in one of two modes, picked automatically from the result shape:

  • Overview mode (many anomalies, cross-entity): severity counts, affected-entities list, by-ML-job breakdown.
  • Detail mode (one anomaly, or filtered to a single entity): entity header, score / actual / typical /

deviation cards, an actual-vs-typical comparison bar, and a time-series when available.

Use the view — don't restate the JSON. Provide a narrative below it:

1. Headline the worst offender: "Top anomaly — frontend memory working set anomalous, score 87 (major), 340% above typical." 2. Group by entity: list the top 3-5 affected entities with one-line summaries (overview mode). 3. Respect the next-step buttons: the view shows investigation_actions as clickable prompts — call them out in your reply ("…or click Blast radius to see infra impact") so the user knows they're there. 4. Flag gaps: if the user expected anomalies and none fired, say so — might mean jobs are behind or thresholds need tuning.

Key principles

  • Let the view do the visual work. The explainer has a severity gauge and per-entity cards. Don't

duplicate them in prose.

  • Anomaly score ≠ severity of the underlying issue. A high score means "unusual," not "broken." Always

cross-reference with what the user is actually seeing.

  • The ML baseline is what the jobs learned from the data's past. Communicate anomalies as "unusual

vs typical behavior learned from prior N days," not as absolute verdicts.

  • Empty result is a signal, not a failure. If the user expected anomalies and none appear at the default

min_score, try lowering it once before concluding "all quiet."

Related skills

FAQ

What does ml-anomalies do?

ml-anomalies skill documents Query Elastic ML anomaly detection results to understand what's behaving unusually, why, and how badly.

When should I use ml-anomalies?

User asks about ml-anomalies, query elastic ml anomaly detection results to understand what's behaving unusually, why, a.

Is this skill safe to install?

Review the Security Audits panel on this page before installing in production.

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.