Featured resource
2025 Tech Upskilling Playbook
Tech Upskilling Playbook

Build future-ready tech teams and hit key business milestones with seven proven plays from industry leaders.

Check it out
  • Lab
    • Libraries: If you want this lab, consider one of these libraries.
    • Cloud
Google Cloud Platform icon
Labs

Visualizing Anomalies in Kibana 7.6

Using Kibana visualizations and dashboards, we can spot anomalies in our data but only if we are very intimately familiar with the data. However, with Kibana’s anomaly detection, we can find unusual data points more quickly and easily than we could by ourselves. Combining the output of anomaly detection machine learning jobs with our visualizations, we can annotate what's normal, and what's not, in real time, without having an intimate knowledge of the dataset. In this hands-on lab, we will explore the annotation ability of the TSVB in Kibana to display anomalous behavior over our time series visualizations.

Google Cloud Platform icon
Lab platform
Lab Info
Level
Intermediate
Last updated
Sep 16, 2025
Duration
2h 30m

Contact sales

By filling out this form and clicking submit, you acknowledge our privacy policy.
Table of Contents
  1. Challenge

    Create and run the ecommerce-sales ML job.
    1. Create a single-metric anomaly detection machine learning job for the ecommerce index pattern.
    2. Use the full flights data as the time range.
    3. Configure the job to analyze the sum of products.price.
    4. Configure the bucket span to be 30 minutes.
    5. Configure the job to ignore sparse data.
    6. Set the job ID to ecommerce-sales.
    7. Create and configure the job to run in realtime.
  2. Challenge

    Create and save the Sales Over Time visualization.
    1. Create the .ml-anomalies-shared index pattern in order to access the anomaly data.
    2. Create a new TSVB time-series visualization for the ecommerce index pattern.
    3. Configure the series to calculate the sum of the products.price field, label it as Sales, and display it as a dollar amount with 2 decimal places (example: 1,234.567 as $1,234.56).
    4. Configure the visualization to hide the legend.
    5. Add an annotation that displays a red line with an exclamation triangle icon whenever an anomaly with a record_score greater than or equal to 50 occurs for the ecommerce-sales machine learning job.
    6. Configure the annotation's tooltip to display the record_score, typical, and actual values of the anomaly.
    7. Save the visualization as Sales Over Time.
  3. Challenge

    Add the Sales Over Time visualization to the eCommerce dashboard.
    1. Edit the eCommerce dashboard.
    2. Add the Sales Over Time visualization and place it wherever you like.
    3. Save the dashboard.
About the author

Pluralsight Skills gives leaders confidence they have the skills needed to execute technology strategy. Technology teams can benchmark expertise across roles, speed up release cycles and build reliable, secure products. By leveraging our expert content, skill assessments and one-of-a-kind analytics, keep up with the pace of change, put the right people on the right projects and boost productivity. It's the most effective path to developing tech skills at scale.

Real skill practice before real-world application

Hands-on Labs are real environments created by industry experts to help you learn. These environments help you gain knowledge and experience, practice without compromising your system, test without risk, destroy without fear, and let you learn from your mistakes. Hands-on Labs: practice your skills before delivering in the real world.

Learn by doing

Engage hands-on with the tools and technologies you’re learning. You pick the skill, we provide the credentials and environment.

Follow your guide

All labs have detailed instructions and objectives, guiding you through the learning process and ensuring you understand every step.

Turn time into mastery

On average, you retain 75% more of your learning if you take time to practice. Hands-on labs set you up for success to make those skills stick.

Get started with Pluralsight