Anomaly detection

Use StackState to detect anomalies in your IT infrastructure
This page describes StackState version 4.3.
The StackState 4.3 version range is End of Life (EOL) and no longer supported. We encourage customers still running the 4.3 version range to upgrade to a more recent release.


StackState can detect anomalies in your IT infrastructure by monitoring the metric streams attached to elements. There are two methods of anomaly detection available:
Each metric stream can use either autonomous or baseline anomaly detection. It is not possible to use both types of anomaly detection on one metric stream at the same time. This means that any metric stream configured with a baseline will not be picked up for anomaly detection by the Autonomous Anomaly detector.

Autonomous anomaly detection

The StackState Autonomous Anomaly Detector (AAD) StackPack works fully autonomously to identify anomalies in your IT environment. When installed and enabled, it will determine for itself the best configuration of its machine learning models and the metric streams that should be prioritized for anomaly detection. No configuration is required although you can influence the selection of telemetry streams by giving a them higher priority.
Once the anomalies are identified, they are displayed in the MetricStream charts as in the example below:
Anomaly example
Additionally, identified anomalies are available as StackState Events and can be viewed in the Events Perspective when event category Anomalies is selected in the filter.
Anomaly events
Finally, anomaly health checks can be configured for the most important metric streams to alert on problems before they occur.
Read more about the Autonomous Anomaly Detector.

Baseline anomaly detection

Baseline anomaly detection is deprecated and will be removed in the StackState 4.4 release. Please use the Autonomous Anomaly Detector).
Each metric stream can have metric baselines manually configured or set by a template. The baselines determine the normal operating values of a metric stream and can be used in health checks and to trigger health state changes. Note that any metric stream with a base line configured will not be picked up for autonomous anomaly detection.