SpecsModelExploreRequirements
SpecsModelExploreRequirements
Anomaly Detector
Detection flow
Severity
Related workflows
Anomaly Detector
Overview
Guide
Twin streams
Links and Communications

Anomaly Detector

The Anomaly Detector is the last stage of the streaming pipeline. It takes windowed aggregates from the Window Aggregator, scores them against per-device baselines, and emits alerts when a device drifts outside expected bounds.

Tuned for signal, not noise

Thresholds are per-device and adaptive. A cold-storage sensor and a rooftop sensor have very different “normal” — a single global threshold would either miss real faults or drown operators in false positives.

Detection flow

Severity

A mild deviation worth recording but not paging on.

Related workflows

This component produces the alerts that drive the end-to-end pipeline: