Thank you for your feedback.
Form temporarily unavailable. Please try again or contact docfeedback@servicenow.com to submit your comments.

Configure the action level of anomaly detection

Log in to subscribe to topics and get notified when content changes.

Configure the action level of anomaly detection

Create a configuration setting rule that refines the level of anomaly detection processing and analysis that is applied to specific CIs and metrics. Set a processing level that reflects the importance of metrics at different stages of implementation, to reduce data load if needed.

Anomaly detection consists of multiple levels of processing. At the lowest level, metric data is gathered from data sources. At the highest level, statistical models are created, anomaly scores are calculated, and anomaly alerts and IT alerts are created. You can apply the full anomaly detection process or a reduced level of processing, for specific data series.

Use the anomaly_detection_action_level configuration setting in a configuration setting rule to set the level of processing for specific CIs and metrics. For example, you can initially set only a small percentage of CIs and metrics to generate anomaly alerts, and later increase that percentage.

Action levels

The anomaly_detection_action_level configuration setting provides action levels starting at 'Metrics only' for basic anomaly processing, and ending at 'IT Alerts' for full processing and analysis.

Action levels from lowest to highest:
Metrics Only
Only gather metrics from the data source without any further processing.
Bounds
'Metrics Only' processing level and in addition creates statistical model and show bounds in Insights Explorer.
Anomaly Scores
'Bounds' processing level and in addition calculates and display anomaly scores.
Anomaly Alerts
'Anomaly Scores' processing level and in addition creates anomaly alerts as applicable.
IT Alerts
'Anomaly Alerts' processing level and in addition creates IT alerts which are based on anomaly alerts, as applicable. Creating IT alerts which are based on anomaly alerts, is equivalent to having an alert promotion rules.
Feedback