Compare commits
4 Commits
docs-artic
...
docs/seo-d
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
00769fa85e | ||
|
|
290e574019 | ||
|
|
0585c0a918 | ||
|
|
e7a7d673df |
@@ -462,11 +462,7 @@ func (ar *AlertingRule) exec(ctx context.Context, ts time.Time, limit int) ([]pr
|
||||
}
|
||||
|
||||
isPartial := isPartialResponse(res)
|
||||
seriesFetched := 0
|
||||
if res.SeriesFetched != nil {
|
||||
seriesFetched = *res.SeriesFetched
|
||||
}
|
||||
ar.logDebugf(ts, nil, "query returned %d series (series_fetched: %d, elapsed: %s, isPartial: %t)", curState.Samples, seriesFetched, curState.Duration, isPartial)
|
||||
ar.logDebugf(ts, nil, "query returned %d series (elapsed: %s, isPartial: %t)", curState.Samples, curState.Duration, isPartial)
|
||||
qFn := func(query string) ([]datasource.Metric, error) {
|
||||
res, _, err := ar.q.Query(ctx, query, ts)
|
||||
return res.Data, err
|
||||
|
||||
@@ -290,8 +290,6 @@ func (g *Group) updateWith(newGroup *Group) error {
|
||||
g.Headers = newGroup.Headers
|
||||
g.NotifierHeaders = newGroup.NotifierHeaders
|
||||
g.Labels = newGroup.Labels
|
||||
g.EvalDelay = newGroup.EvalDelay
|
||||
g.evalAlignment = newGroup.evalAlignment
|
||||
g.Limit = newGroup.Limit
|
||||
g.checksum = newGroup.checksum
|
||||
g.Rules = newRules
|
||||
@@ -339,7 +337,7 @@ func (g *Group) Init() {
|
||||
i := g.Interval.Seconds()
|
||||
return i
|
||||
})
|
||||
g.metrics.iterationLimit = g.metrics.set.NewGauge(fmt.Sprintf(`vmalert_group_rule_results_limit{%s}`, labels), func() float64 {
|
||||
g.metrics.iterationLimit = g.metrics.set.NewGauge(fmt.Sprintf(`vmalert_rule_group_results_limit{%s}`, labels), func() float64 {
|
||||
g.mu.RLock()
|
||||
limit := g.Limit
|
||||
g.mu.RUnlock()
|
||||
@@ -375,7 +373,7 @@ func (g *Group) Start(ctx context.Context, rw remotewrite.RWClient, rr datasourc
|
||||
g.mu.Lock()
|
||||
err := g.updateWith(ng)
|
||||
if err != nil {
|
||||
logger.Errorf("group %q (file=%q): failed to update: %s", g.Name, g.File, err)
|
||||
logger.Errorf("group %q: failed to update: %s", g.Name, err)
|
||||
g.mu.Unlock()
|
||||
continue
|
||||
}
|
||||
@@ -414,7 +412,7 @@ func (g *Group) Start(ctx context.Context, rw remotewrite.RWClient, rr datasourc
|
||||
errs := e.execConcurrently(ctx, g.Rules, ts, g.Concurrency, resolveDuration, g.Limit)
|
||||
for err := range errs {
|
||||
if err != nil {
|
||||
logger.Errorf("group %q (file=%q): %s", g.Name, g.File, err)
|
||||
logger.Errorf("group %q: %s", g.Name, err)
|
||||
}
|
||||
}
|
||||
g.metrics.iterationDuration.UpdateDuration(start)
|
||||
@@ -443,17 +441,17 @@ func (g *Group) Start(ctx context.Context, rw remotewrite.RWClient, rr datasourc
|
||||
if rr != nil {
|
||||
err := g.restore(ctx, rr, realEvalTS, *remoteReadLookBack)
|
||||
if err != nil {
|
||||
logger.Errorf("error while restoring ruleState for group %q (file=%q): %s", g.Name, g.File, err)
|
||||
logger.Errorf("error while restoring ruleState for group %q: %s", g.Name, err)
|
||||
}
|
||||
}
|
||||
|
||||
for {
|
||||
select {
|
||||
case <-ctx.Done():
|
||||
logger.Infof("group %q (file=%q): context cancelled", g.Name, g.File)
|
||||
logger.Infof("group %q: context cancelled", g.Name)
|
||||
return
|
||||
case <-g.doneCh:
|
||||
logger.Infof("group %q (file=%q): received stop signal", g.Name, g.File)
|
||||
logger.Infof("group %q: received stop signal", g.Name)
|
||||
return
|
||||
case ng := <-g.updateCh:
|
||||
g.mu.Lock()
|
||||
@@ -467,7 +465,7 @@ func (g *Group) Start(ctx context.Context, rw remotewrite.RWClient, rr datasourc
|
||||
|
||||
err := g.updateWith(ng)
|
||||
if err != nil {
|
||||
logger.Errorf("group %q (file=%q): failed to update: %s", g.Name, g.File, err)
|
||||
logger.Errorf("group %q: failed to update: %s", g.Name, err)
|
||||
g.mu.Unlock()
|
||||
continue
|
||||
}
|
||||
@@ -545,8 +543,8 @@ func (g *Group) delayBeforeStart(ts time.Time, maxDelay time.Duration) time.Dura
|
||||
|
||||
func (g *Group) infof(format string, args ...any) {
|
||||
msg := fmt.Sprintf(format, args...)
|
||||
logger.Infof("group %q (file=%q; interval=%v; eval_offset=%v; concurrency=%d) %s",
|
||||
g.Name, g.File, g.Interval, g.EvalOffset, g.Concurrency, msg)
|
||||
logger.Infof("group %q %s; interval=%v; eval_offset=%v; concurrency=%d",
|
||||
g.Name, msg, g.Interval, g.EvalOffset, g.Concurrency)
|
||||
}
|
||||
|
||||
// Replay performs group replay
|
||||
|
||||
@@ -78,12 +78,6 @@ func TestUpdateWith(t *testing.T) {
|
||||
if g.Debug != expect.Debug {
|
||||
t.Fatalf("expected to have debug %v; got %v", expect.Debug, g.Debug)
|
||||
}
|
||||
if !durationPtrEqual(g.EvalDelay, expect.EvalDelay) {
|
||||
t.Fatalf("expected to have eval_delay %v; got %v", expect.EvalDelay, g.EvalDelay)
|
||||
}
|
||||
if !boolPtrEqual(g.evalAlignment, expect.evalAlignment) {
|
||||
t.Fatalf("expected to have eval_alignment %v; got %v", expect.evalAlignment, g.evalAlignment)
|
||||
}
|
||||
}
|
||||
|
||||
// new rule
|
||||
@@ -243,37 +237,6 @@ func TestUpdateWith(t *testing.T) {
|
||||
{Alert: "foo1", Debug: &debug},
|
||||
},
|
||||
})
|
||||
|
||||
// update group evaluation settings
|
||||
evalDelay := promutil.NewDuration(time.Minute)
|
||||
evalAlignment := false
|
||||
f(config.Group{
|
||||
Rules: []config.Rule{{
|
||||
Record: "foo",
|
||||
Expr: "max(up)",
|
||||
}},
|
||||
}, config.Group{
|
||||
EvalDelay: evalDelay,
|
||||
EvalAlignment: &evalAlignment,
|
||||
Rules: []config.Rule{{
|
||||
Record: "foo",
|
||||
Expr: "min(up)",
|
||||
}},
|
||||
})
|
||||
}
|
||||
|
||||
func durationPtrEqual(a, b *time.Duration) bool {
|
||||
if a == nil || b == nil {
|
||||
return a == b
|
||||
}
|
||||
return *a == *b
|
||||
}
|
||||
|
||||
func boolPtrEqual(a, b *bool) bool {
|
||||
if a == nil || b == nil {
|
||||
return a == b
|
||||
}
|
||||
return *a == *b
|
||||
}
|
||||
|
||||
func TestUpdateDuringRandSleep(t *testing.T) {
|
||||
|
||||
@@ -208,11 +208,7 @@ func (rr *RecordingRule) exec(ctx context.Context, ts time.Time, limit int) ([]p
|
||||
return nil, curState.Err
|
||||
}
|
||||
|
||||
seriesFetched := 0
|
||||
if res.SeriesFetched != nil {
|
||||
seriesFetched = *res.SeriesFetched
|
||||
}
|
||||
rr.logDebugf(ts, "query returned %d samples (series_fetched: %d, elapsed: %s, isPartial: %t)", curState.Samples, seriesFetched, curState.Duration, isPartialResponse(res))
|
||||
rr.logDebugf(ts, "query returned %d samples (elapsed: %s, isPartial: %t)", curState.Samples, curState.Duration, isPartialResponse(res))
|
||||
|
||||
qMetrics := res.Data
|
||||
numSeries := len(qMetrics)
|
||||
|
||||
@@ -1,5 +0,0 @@
|
||||
<svg width="48" height="48" fill="#020202" xmlns="http://www.w3.org/2000/svg">
|
||||
<path d="M24.5475 0C10.3246.0265251 1.11379 3.06365 4.40623 6.10077c0 0 12.32997 11.23333 16.58217 14.84083.8131.6896 2.1728 1.1936 3.5191 1.2201h.1199c1.3463-.0265 2.706-.5305 3.5191-1.2201 4.2522-3.5942 16.5422-14.84083 16.5422-14.84083C48.0478 3.06365 38.8636.0265251 24.6674 0"/>
|
||||
<path d="M28.1579 27.0159c-.8131.6896-2.1728 1.1936-3.5191 1.2201h-.12c-1.3463-.0265-2.7059-.5305-3.519-1.2201-2.9725-2.5067-13.35639-11.87-17.26201-15.3979v5.4112c0 .5968.22661 1.3793.6265 1.7506C7.00358 21.1936 17.2675 30.5437 20.9731 33.6737c.8132.6896 2.1728 1.1936 3.5191 1.2201h.12c1.3463-.0265 2.7059-.5305 3.519-1.2201 3.679-3.13 13.9429-12.4536 16.6089-14.8939.4132-.3713.6265-1.1538.6265-1.7506V11.618c-3.9323 3.5411-14.3162 12.931-17.2354 15.3979h.0267Z"/>
|
||||
<path d="M28.1579 39.748c-.8131.6897-2.1728 1.1937-3.5191 1.2202h-.12c-1.3463-.0265-2.7059-.5305-3.519-1.2202-2.9725-2.4933-13.35639-11.8567-17.26201-15.3978v5.4111c0 .5969.22661 1.3793.6265 1.7507C7.00358 33.9258 17.2675 43.2759 20.9731 46.4058c.8132.6897 2.1728 1.1937 3.5191 1.2202h.12c1.3463-.0265 2.7059-.5305 3.519-1.2202 3.679-3.1299 13.9429-12.4535 16.6089-14.8938.4132-.3714.6265-1.1538.6265-1.7507v-5.4111c-3.9323 3.5411-14.3162 12.931-17.2354 15.3978h.0267Z"/>
|
||||
</svg>
|
||||
|
Before Width: | Height: | Size: 1.3 KiB |
197
app/vmselect/vmui/assets/index-B1dXK3k7.js
Normal file
1
app/vmselect/vmui/assets/index-BJqoElx2.css
Normal file
1
app/vmselect/vmui/favicon.svg
Normal file
@@ -0,0 +1 @@
|
||||
<svg width="48" height="48" fill="none" xmlns="http://www.w3.org/2000/svg"><path d="M24.5475 0C10.3246.0265251 1.11379 3.06365 4.40623 6.10077c0 0 12.32997 11.23333 16.58217 14.84083.8131.6896 2.1728 1.1936 3.5191 1.2201h.1199c1.3463-.0265 2.706-.5305 3.5191-1.2201 4.2522-3.5942 16.5422-14.84083 16.5422-14.84083C48.0478 3.06365 38.8636.0265251 24.6674 0" fill="#020202"/><path d="M28.1579 27.0159c-.8131.6896-2.1728 1.1936-3.5191 1.2201h-.12c-1.3463-.0265-2.7059-.5305-3.519-1.2201-2.9725-2.5067-13.35639-11.87-17.26201-15.3979v5.4112c0 .5968.22661 1.3793.6265 1.7506C7.00358 21.1936 17.2675 30.5437 20.9731 33.6737c.8132.6896 2.1728 1.1936 3.5191 1.2201h.12c1.3463-.0265 2.7059-.5305 3.519-1.2201 3.679-3.13 13.9429-12.4536 16.6089-14.8939.4132-.3713.6265-1.1538.6265-1.7506V11.618c-3.9323 3.5411-14.3162 12.931-17.2354 15.3979h.0267Z" fill="#020202"/><path d="M28.1579 39.748c-.8131.6897-2.1728 1.1937-3.5191 1.2202h-.12c-1.3463-.0265-2.7059-.5305-3.519-1.2202-2.9725-2.4933-13.35639-11.8567-17.26201-15.3978v5.4111c0 .5969.22661 1.3793.6265 1.7507C7.00358 33.9258 17.2675 43.2759 20.9731 46.4058c.8132.6897 2.1728 1.1937 3.5191 1.2202h.12c1.3463-.0265 2.7059-.5305 3.519-1.2202 3.679-3.1299 13.9429-12.4535 16.6089-14.8938.4132-.3714.6265-1.1538.6265-1.7507v-5.4111c-3.9323 3.5411-14.3162 12.931-17.2354 15.3978h.0267Z" fill="#020202"/></svg>
|
||||
|
After Width: | Height: | Size: 1.3 KiB |
@@ -2,9 +2,9 @@
|
||||
<html lang="en">
|
||||
<head>
|
||||
<meta charset="utf-8"/>
|
||||
<link id="favicon" rel="icon" href="./assets/favicon.svg" />
|
||||
<link rel="apple-touch-icon" href="./assets/favicon.svg" />
|
||||
<link id="mask-icon" rel="mask-icon" href="./assets/favicon.svg" color="#000000">
|
||||
<link rel="icon" href="./favicon.svg"/>
|
||||
<link rel="apple-touch-icon" href="./favicon.svg"/>
|
||||
<link rel="mask-icon" href="./favicon.svg" color="#000000">
|
||||
|
||||
<meta name="robots" content="noindex">
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1, maximum-scale=5"/>
|
||||
@@ -37,11 +37,11 @@
|
||||
<meta property="og:title" content="UI for VictoriaMetrics">
|
||||
<meta property="og:url" content="https://victoriametrics.com/">
|
||||
<meta property="og:description" content="Explore and troubleshoot your VictoriaMetrics data">
|
||||
<script type="module" crossorigin src="./assets/index-BiDX4bB6.js"></script>
|
||||
<script type="module" crossorigin src="./assets/index-B1dXK3k7.js"></script>
|
||||
<link rel="modulepreload" crossorigin href="./assets/rolldown-runtime-CNC7AqOf.js">
|
||||
<link rel="modulepreload" crossorigin href="./assets/vendor-DwJYpOdw.js">
|
||||
<link rel="stylesheet" crossorigin href="./assets/vendor-CnsZ1jie.css">
|
||||
<link rel="stylesheet" crossorigin href="./assets/index-CymA7XYg.css">
|
||||
<link rel="stylesheet" crossorigin href="./assets/index-BJqoElx2.css">
|
||||
</head>
|
||||
<body>
|
||||
<noscript>You need to enable JavaScript to run this app.</noscript>
|
||||
|
||||
@@ -3,7 +3,7 @@
|
||||
"name": "vmui",
|
||||
"icons": [
|
||||
{
|
||||
"src": "./assets/favicon.svg",
|
||||
"src": "favicon.svg",
|
||||
"sizes": "any",
|
||||
"type": "image/svg+xml"
|
||||
}
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
FROM golang:1.26.6 AS build-web-stage
|
||||
FROM golang:1.26.5 AS build-web-stage
|
||||
COPY build /build
|
||||
|
||||
WORKDIR /build
|
||||
|
||||
@@ -7,7 +7,7 @@ ROOT_IMAGE ?= alpine:3.24.1
|
||||
ROOT_IMAGE_SCRATCH ?= scratch
|
||||
CERTS_IMAGE := alpine:3.24.1
|
||||
|
||||
GO_BUILDER_IMAGE := golang:1.26.6
|
||||
GO_BUILDER_IMAGE := golang:1.26.5
|
||||
|
||||
BUILDER_IMAGE := local/builder:2.0.0-$(shell echo $(GO_BUILDER_IMAGE) | tr :/ __)-1
|
||||
BASE_IMAGE := local/base:1.1.4-$(shell echo $(ROOT_IMAGE) | tr :/ __)-$(shell echo $(CERTS_IMAGE) | tr :/ __)
|
||||
|
||||
@@ -59,7 +59,7 @@ services:
|
||||
- '--external.alert.source=explore?orgId=1&left=["now-1h","now","VictoriaMetrics",{"expr": },{"mode":"Metrics"},{"ui":[true,true,true,"none"]}]'
|
||||
restart: always
|
||||
vmanomaly:
|
||||
image: victoriametrics/vmanomaly:v1.30.2
|
||||
image: victoriametrics/vmanomaly:v1.30.1
|
||||
depends_on:
|
||||
- "victoriametrics"
|
||||
ports:
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
schedulers:
|
||||
periodic:
|
||||
infer_every: "1m"
|
||||
fit_every: "1000d" # bootstrap-only schedule; use a finite cadence if accumulated state must be reset
|
||||
fit_every: "100w" # the online model keeps learning during inference
|
||||
fit_window: "2w"
|
||||
|
||||
models:
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
---
|
||||
title: AI tools
|
||||
description: "MCP servers, skills, and AI assistant integrations for querying metrics, logs, and traces with natural language."
|
||||
weight: 61
|
||||
menu:
|
||||
docs:
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
---
|
||||
weight: 7
|
||||
title: CHANGELOG
|
||||
description: "Release history for vmanomaly."
|
||||
menu:
|
||||
docs:
|
||||
identifier: "vmanomaly-changelog"
|
||||
@@ -16,23 +17,6 @@ Please find the changelog for VictoriaMetrics Anomaly Detection below.
|
||||
|
||||
{{% collapse name="2026" open=true %}}
|
||||
|
||||
## v1.30.2
|
||||
Released: 2026-08-13
|
||||
|
||||
- UI: Updated [vmanomaly UI](https://docs.victoriametrics.com/anomaly-detection/ui/) from [v1.8.1](https://docs.victoriametrics.com/anomaly-detection/ui/#v181) to [v1.8.2](https://docs.victoriametrics.com/anomaly-detection/ui/#v182), fixing tenant discovery and switching for multitenant VictoriaMetrics datasources.
|
||||
|
||||
- FEATURE: Added **query**-level [`data_range`, `detection_direction`, `min_dev_from_expected`, and `min_rel_dev_from_expected`](https://docs.victoriametrics.com/anomaly-detection/components/reader/#per-query-parameters). Model-level placement is deprecated but remains a compatible fallback.
|
||||
|
||||
- IMPROVEMENT: Added [`reader.workers`](https://docs.victoriametrics.com/anomaly-detection/components/reader/#config-parameters) to cap concurrent datasource requests and disk-streamed query chunks; `0` selects an automatic bound.
|
||||
|
||||
- IMPROVEMENT: Added [`settings.native_threads_per_worker`](https://docs.victoriametrics.com/anomaly-detection/components/settings/#parallelization) to reduce [native-thread oversubscription](https://scikit-learn.org/stable/computing/parallelism.html#oversubscription-spawning-too-many-threads), throttling risk, fit latency, and memory. For example, with 16 CPUs/workers, [Temporal Envelope](https://docs.victoriametrics.com/anomaly-detection/components/models/#temporal-envelope) fit time fell 70.6% for 1,000 univariate models and 11.5% for 100 x 10-channel grouped models; inference was unchanged.
|
||||
|
||||
- IMPROVEMENT: Removed temporary fit-data generations after all dependent models finish and commit, while safely retaining failed or overlapping generations.
|
||||
|
||||
- IMPROVEMENT: Reduced disk-backed grouped multivariate memory and fit latency without model or state migration. For example, 100 x 100-channel four-week fits cut peak PSS/fit time by 63%/56% for [Temporal Envelope](https://docs.victoriametrics.com/anomaly-detection/components/models/#temporal-envelope).
|
||||
|
||||
- BUGFIX: Made [multivariate models](https://docs.victoriametrics.com/anomaly-detection/components/models/#multivariate-models) independent of input channel order when the fitted channel set matches; missing, extra, or duplicate channels remain rejected.
|
||||
|
||||
## v1.30.1
|
||||
Released: 2026-08-06
|
||||
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
---
|
||||
weight: 6
|
||||
title: FAQ
|
||||
description: "Frequently asked questions about vmanomaly."
|
||||
menu:
|
||||
docs:
|
||||
identifier: "vmanomaly-faq"
|
||||
@@ -33,7 +34,7 @@ Please see example graph illustrating this logic below:
|
||||
|
||||

|
||||
|
||||
> Additional post-processing logic may be applied to produced anomaly scores when query policies such as [`min_dev_from_expected`](https://docs.victoriametrics.com/anomaly-detection/components/models/#minimal-deviation-from-expected) or [`detection_direction`](https://docs.victoriametrics.com/anomaly-detection/components/models/#detection-direction) are configured. Follow the links for details.
|
||||
> p.s. please note that additional post-processing logic might be applied to produced anomaly scores, if common arguments like [`min_dev_from_expected`](https://docs.victoriametrics.com/anomaly-detection/components/models/#minimal-deviation-from-expected) or [`detection_direction`](https://docs.victoriametrics.com/anomaly-detection/components/models/#detection-direction) are enabled for a particular model. Follow the links above for the explanations.
|
||||
|
||||
|
||||
## How does vmanomaly work?
|
||||
@@ -135,7 +136,7 @@ Still not 100% sure what to use? We are [here to help](https://docs.victoriametr
|
||||
|
||||
## Incorporating domain knowledge
|
||||
|
||||
Anomaly detection models can significantly improve when incorporating business-specific assumptions about the data and what constitutes an anomaly. `vmanomaly` supports [business policies](https://docs.victoriametrics.com/anomaly-detection/components/models/#common-args) across built-in models to **reduce [false positives](https://victoriametrics.com/blog/victoriametrics-anomaly-detection-handbook-chapter-1/#false-positive)** and **align model behavior with business needs**, for example:
|
||||
Anomaly detection models can significantly improve when incorporating business-specific assumptions about the data and what constitutes an anomaly. `vmanomaly` supports various [business-side configuration parameters](https://docs.victoriametrics.com/anomaly-detection/components/models/#common-args) across all built-in models to **reduce [false positives](https://victoriametrics.com/blog/victoriametrics-anomaly-detection-handbook-chapter-1/#false-positive)** and **align model behavior with business needs**, for example:
|
||||
|
||||
- **Setting `detection_direction`** - use [`detection_direction`](https://docs.victoriametrics.com/anomaly-detection/components/models/#detection-direction) to specify whether anomalies occur **above or below expectations**:
|
||||
- Set to `above_expected` for metrics like error rates, where spikes indicate anomalies.
|
||||
@@ -163,7 +164,7 @@ Then, the following config may be used to benefit from incorporating domain know
|
||||
schedulers:
|
||||
periodic_http:
|
||||
class: periodic
|
||||
fit_every: 1000d
|
||||
fit_every: 12w
|
||||
fit_window: 1w
|
||||
infer_every: 1m
|
||||
# other schedulers ...
|
||||
@@ -172,19 +173,18 @@ reader:
|
||||
queries:
|
||||
percentage_4xx:
|
||||
expr: respective_metricsQL_expr
|
||||
data_range: [0, 0.05] # query-level business policy from v1.30.2; error rates >5% trigger anomaly score >1
|
||||
detection_direction: 'above_expected' # query-level from v1.30.2; only spikes are anomalous
|
||||
min_dev_from_expected: [0, 0.005] # query-level from v1.30.2; ignore upward deviations below 0.5%
|
||||
min_rel_dev_from_expected: [0, 10] # query-level from v1.30.2; ignore upward deviations below 10%
|
||||
data_range: [0, 0.05] # to automatically trigger anomaly score > 1 for error rates > 5%
|
||||
step: 1m
|
||||
models:
|
||||
# other models ...
|
||||
zscore: # let it be online Z-score, for simplicity
|
||||
class: zscore_online # online model update itself each infer call, resulting in resource-efficient setups
|
||||
z_threshold: 3.0
|
||||
decay: 0.99 # give more weight to recent data while using the bootstrap-only fit schedule
|
||||
schedulers: ['periodic_http']
|
||||
queries: ['percentage_4xx']
|
||||
detection_direction: 'above_expected' # as interested only in spikes, drops are OK
|
||||
min_dev_from_expected: [0, 0.005] # <0.5% deviations vs expected values should be neglected, generating anomaly score == 0
|
||||
min_rel_dev_from_expected: [0, 0.1] # <10% relative deviations vs expected values should be neglected, generating anomaly score == 0
|
||||
# to align predictions to be within [0, 5%] interval, defined in reader.queries.percentage_4xx.data_range
|
||||
clip_predictions: True
|
||||
# specify output series produced by vmanomaly to be written to VictoriaMetrics in `writer`
|
||||
@@ -230,7 +230,7 @@ models:
|
||||
schedulers: ['scheduler_alias'] # if omitted, all the defined schedulers will be attached
|
||||
queries: ['query_alias1'] # if omitted, all the defined queries will be attached
|
||||
# https://docs.victoriametrics.com/anomaly-detection/components/models/#provide-series
|
||||
provide_series: ['anomaly_score']
|
||||
provide_series: ['anomaly_score']
|
||||
# ... other models
|
||||
|
||||
reader:
|
||||
@@ -256,7 +256,6 @@ Configuration above will produce N intervals of full length (`fit_window`=14d +
|
||||
|
||||
`vmanomaly` can generate future forecasts with [Temporal Envelope](https://docs.victoriametrics.com/anomaly-detection/components/models/#temporal-envelope) {{% available_from "v1.30.0" anomaly %}}, the preferred online forecasting model. [ProphetModel](https://docs.victoriametrics.com/anomaly-detection/components/models/#prophet) {{% available_from "v1.25.3" anomaly %}} also supports forecasting for existing offline configurations. Forecasts help with capacity planning, resource allocation, or trend analysis when the underlying data is complex and exceeds what inline MetricsQL queries, including [predict_linear](https://docs.victoriametrics.com/victoriametrics/metricsql/#predict_linear), can handle.
|
||||
|
||||
> [!WARNING]
|
||||
> However, please note that this mode should be used with care, as the model will produce `yhat_{h}` (and probably `yhat_lower_{h}`, and `yhat_upper_{h}`) time series **for each timeseries returned by input queries and for each forecasting horizon specified in `forecast_at` argument, which can lead to a significant increase in the number of active timeseries in VictoriaMetrics TSDB**.
|
||||
|
||||
Here's an example of how to produce forecasts using `vmanomaly` and combine it with the regular model, e.g. to estimate daily outcomes for a disk usage metric:
|
||||
@@ -266,12 +265,12 @@ Here's an example of how to produce forecasts using `vmanomaly` and combine it w
|
||||
schedulers:
|
||||
periodic_5m: # this scheduler will be used to produce anomaly scores each 5 minutes using "regular" simple model
|
||||
class: 'periodic'
|
||||
fit_every: '1000d'
|
||||
fit_every: '100w'
|
||||
fit_window: '3d'
|
||||
infer_every: '5m'
|
||||
periodic_forecast: # this scheduler will be used to produce forecasts each 24h using "daily" model
|
||||
class: 'periodic'
|
||||
fit_every: '1000d'
|
||||
fit_every: '1000w'
|
||||
fit_window: '730d' # to fit the model on 2 years of data to account for seasonality and holidays
|
||||
infer_every: '24h'
|
||||
# https://docs.victoriametrics.com/anomaly-detection/components/reader/#vm-reader
|
||||
@@ -291,7 +290,6 @@ reader:
|
||||
1h
|
||||
)
|
||||
data_range: [0, 1]
|
||||
detection_direction: 'above_expected' # query-level from v1.30.2
|
||||
# step: '1m' # default will be inherited from sampling_period
|
||||
disk_usage_perc_1d:
|
||||
expr: |
|
||||
@@ -303,15 +301,14 @@ reader:
|
||||
)
|
||||
step: '1d' # override default step to 1d, as we want to produce daily forecasts
|
||||
data_range: [0, 1]
|
||||
detection_direction: 'above_expected' # query-level from v1.30.2
|
||||
# https://docs.victoriametrics.com/anomaly-detection/components/models/
|
||||
models:
|
||||
quantile_5m:
|
||||
class: 'quantile_online' # online model, which updates itself each infer call
|
||||
queries: ['disk_usage_perc_5m']
|
||||
schedulers: ['periodic_5m']
|
||||
decay: 0.99 # give more weight to recent data while using the bootstrap-only fit schedule
|
||||
clip_predictions: True
|
||||
detection_direction: 'above_expected' # as we are interested in spikes in capacity planning
|
||||
quantiles: [0.25, 0.5, 0.75] # to produce median and upper quartiles
|
||||
iqr_threshold: 2.0
|
||||
|
||||
@@ -319,9 +316,8 @@ models:
|
||||
class: 'temporal_envelope'
|
||||
queries: ['disk_usage_perc_1d']
|
||||
schedulers: ['periodic_forecast']
|
||||
alpha: 0.005 # capture the changes faster if increased
|
||||
loss_reactivity: 3 # allow new deviations to update the envelope
|
||||
clip_predictions: True
|
||||
detection_direction: 'above_expected' # as we are interested in spikes in capacity planning
|
||||
forecast_at: ['3d', '7d'] # this will produce forecasts for 3 and 7 days ahead
|
||||
provide_series: ['yhat', 'yhat_upper'] # to write forecasts back to VictoriaMetrics, omitting `yhat_lower` as it is not needed in this example
|
||||
seasonalities: [dow_smooth]
|
||||
@@ -430,15 +426,13 @@ For information on migrating between different versions of `vmanomaly`, please r
|
||||
|
||||
> {{% available_from "v1.24.0" anomaly %}} This feature is best used in conjunction with [stateful mode](https://docs.victoriametrics.com/anomaly-detection/components/settings/#state-restoration) to ensure that the model state is preserved across service restarts.
|
||||
|
||||
> {{% available_from "v1.30.2" anomaly %}} Scheduler-managed fit data is **temporary**. It is removed after every dependent univariate or multivariate model completes fitting and commits its state, rather than being retained until the next `fit_every` cycle. Model dumps and state metadata remain available for restoration.
|
||||
|
||||
Here's an example of how to set it up in docker-compose using volumes:
|
||||
```yaml
|
||||
services:
|
||||
# ...
|
||||
vmanomaly:
|
||||
container_name: vmanomaly
|
||||
image: victoriametrics/vmanomaly:v1.30.2
|
||||
image: victoriametrics/vmanomaly:v1.30.1
|
||||
# ...
|
||||
restart: always
|
||||
volumes:
|
||||
@@ -509,7 +503,7 @@ settings:
|
||||
schedulers:
|
||||
periodic:
|
||||
class: 'periodic'
|
||||
fit_every: '1000d'
|
||||
fit_every: '180d' # we need only initial fit to start
|
||||
fit_window: '4h' # reduced window, especially if the data doesn't have strong seasonality
|
||||
infer_every: '1m' # the model will be updated during each infer call
|
||||
# other schedulers ...
|
||||
@@ -517,7 +511,7 @@ models:
|
||||
zscore_example:
|
||||
class: 'zscore_online'
|
||||
min_n_samples_seen: 120 # i.e. minimal relevant seasonality or (initial) fit_window / sampling_period
|
||||
decay: 0.99 # decay factor to control how fast the model adapts to new data, the lower, the faster it adapts
|
||||
decay: 0.999 # decay factor to control how fast the model adapts to new data, the lower, the faster it adapts
|
||||
schedulers: ['periodic']
|
||||
# other model params ...
|
||||
# other config sections ...
|
||||
@@ -531,11 +525,11 @@ As a result, switching from the offline Z-score model to the Online Z-score mode
|
||||
|
||||
**New configuration**:
|
||||
- `fit_window`: 4 hours
|
||||
- `fit_every`: 1000 days ( >1 week)
|
||||
- `fit_every`: 180 days ( >1 week)
|
||||
|
||||
The old configuration would perform 168 (hours in a week) `fit` calls, each using 2 days (48 hours) of data, totaling 168 * 48 = 8064 hours of data for each timeseries returned.
|
||||
|
||||
The new configuration performs only 1 `fit` call in 1000 days, using 4 hours of data initially, totaling 4 hours of data, which is **magnitudes smaller**.
|
||||
The new configuration performs only 1 `fit` call in 180 days, using 4 hours of data initially, totaling 4 hours of data, which is **magnitudes smaller**.
|
||||
|
||||
P.s. `infer` data volume will remain the same for both models, so it does not affect the overall calculations.
|
||||
|
||||
@@ -563,7 +557,9 @@ models:
|
||||
temporal_envelope:
|
||||
class: temporal_envelope
|
||||
# other model args
|
||||
queries: ['sum_alerts']
|
||||
queries: [
|
||||
'sum_alerts',
|
||||
]
|
||||
# other config sections
|
||||
```
|
||||
|
||||
@@ -583,7 +579,9 @@ models:
|
||||
temporal_envelope:
|
||||
class: temporal_envelope
|
||||
# other model args
|
||||
queries: ['sum_alerts']
|
||||
queries: [
|
||||
'sum_alerts',
|
||||
]
|
||||
# other config sections
|
||||
```
|
||||
|
||||
@@ -601,7 +599,10 @@ models:
|
||||
temporal_envelope:
|
||||
class: temporal_envelope
|
||||
# other model args
|
||||
queries: ['sum_alerts_pending', 'sum_alerts_firing']
|
||||
queries: [
|
||||
'sum_alerts_pending',
|
||||
'sum_alerts_firing',
|
||||
]
|
||||
# other config sections
|
||||
```
|
||||
|
||||
@@ -651,12 +652,10 @@ options:
|
||||
Minimum level to log. Default: INFO
|
||||
```
|
||||
|
||||
For a side-by-side comparison of all split modes and their resulting sub-configurations, see [splitting strategies](https://docs.victoriametrics.com/anomaly-detection/scaling-vmanomaly/#splitting-strategies).
|
||||
|
||||
Here’s an example of using the config splitter to divide configurations based on the `extra_filters` argument from the reader section:
|
||||
|
||||
```sh
|
||||
docker pull victoriametrics/vmanomaly:v1.30.2 && docker image tag victoriametrics/vmanomaly:v1.30.2 vmanomaly
|
||||
docker pull victoriametrics/vmanomaly:v1.30.1 && docker image tag victoriametrics/vmanomaly:v1.30.1 vmanomaly
|
||||
```
|
||||
|
||||
```sh
|
||||
@@ -689,11 +688,10 @@ reader:
|
||||
# ...
|
||||
queries:
|
||||
extra_big_query: metricsql_expression_returning_too_many_timeseries
|
||||
extra_filters: [
|
||||
extra_filters:
|
||||
# suppose you have a label `region` with values to deterministically define such subsets
|
||||
'{env="region_name_1"}',
|
||||
- '{env="region_name_1"}'
|
||||
# ...
|
||||
]
|
||||
```
|
||||
|
||||
```yaml
|
||||
@@ -703,11 +701,10 @@ reader:
|
||||
# ...
|
||||
queries:
|
||||
extra_big_query: metricsql_expression_returning_too_many_timeseries
|
||||
extra_filters: [
|
||||
extra_filters:
|
||||
# suppose you have a label `region` with values to deterministically define such subsets
|
||||
'{region="region_name_2"}',
|
||||
- '{region="region_name_2"}'
|
||||
# ...
|
||||
]
|
||||
```
|
||||
|
||||
## Monitoring vmanomaly
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
---
|
||||
weight: 5
|
||||
title: Migration
|
||||
description: "Migration guide to the latest vmanomaly version."
|
||||
menu:
|
||||
docs:
|
||||
identifier: "vmanomaly-migration"
|
||||
@@ -45,7 +46,7 @@ There are 2 types of compatibility to consider when migrating in stateful mode:
|
||||
|
||||
| Group start | Group end | Compatibility | Notes |
|
||||
|---------|--------- |------------|-------|
|
||||
| [v1.29.1](https://docs.victoriametrics.com/anomaly-detection/changelog/#v1291) | [v1.30.2](https://docs.victoriametrics.com/anomaly-detection/changelog/#v1302) | Fully Compatible | v1.30.0 adds new [Temporal Envelope](https://docs.victoriametrics.com/anomaly-detection/components/models/#temporal-envelope) model state without changing the compatibility of existing model and data artifacts. v1.30.2 remains compatible with v1.30.1 state and its compatible predecessors; no persisted-state migration is required. |
|
||||
| [v1.29.1](https://docs.victoriametrics.com/anomaly-detection/changelog/#v1291) | [v1.30.1](https://docs.victoriametrics.com/anomaly-detection/changelog/#v1301) | Fully Compatible | v1.30.0 adds new [Temporal Envelope](https://docs.victoriametrics.com/anomaly-detection/components/models/#temporal-envelope) model state without changing the compatibility of existing model and data artifacts. v1.30.1 remains compatible with v1.30.0 state and its compatible predecessors. |
|
||||
| [v1.28.7](https://docs.victoriametrics.com/anomaly-detection/changelog/#v1287) | [v1.29.0](https://docs.victoriametrics.com/anomaly-detection/changelog/#v1290) | Partially compatible* | Dumped models of class [prophet](https://docs.victoriametrics.com/anomaly-detection/components/models/#prophet) and [seasonal quantile](https://docs.victoriametrics.com/anomaly-detection/components/models/#online-seasonal-quantile) have problems with loading to [v1.29.0](https://docs.victoriametrics.com/anomaly-detection/changelog/#v1290) due to dropped `pytz` library. **Upgrading directly from v1.28.7 to [v1.29.1](https://docs.victoriametrics.com/anomaly-detection/changelog/#v1291) with a fix is suggested** |
|
||||
| [v1.26.0](https://docs.victoriametrics.com/anomaly-detection/changelog/#v1262) | [v1.28.7](https://docs.victoriametrics.com/anomaly-detection/changelog/#v1287) | Fully Compatible | [v1.28.0](https://docs.victoriametrics.com/anomaly-detection/changelog/#v1280) introduced [rolling](https://docs.victoriametrics.com/anomaly-detection/components/models/#rolling-models) model class drop in favor of [online](https://docs.victoriametrics.com/anomaly-detection/components/models/#online-models) models (`rolling_quantile` and `std` models), however, it does not impact compatibility, as artifacts were not produced by default for rolling models. Also, offline `mad` and `zscore` models are redirecting to their respective online counterparts since [v1.28.4](https://docs.victoriametrics.com/anomaly-detection/changelog/#v1284). |
|
||||
| [v1.25.3](https://docs.victoriametrics.com/anomaly-detection/changelog/#v1253) | [v1.26.0](https://docs.victoriametrics.com/anomaly-detection/changelog/#v1270) | Partially Compatible* | [v1.25.3](https://docs.victoriametrics.com/anomaly-detection/changelog/#v1253) introduced `forecast_at` argument for base [univariate](https://docs.victoriametrics.com/anomaly-detection/components/models/#univariate-models) and `Prophet` [models](https://docs.victoriametrics.com/anomaly-detection/components/models/#prophet), however, itself remains backward-reversible from newer states like [v1.26.2](https://docs.victoriametrics.com/anomaly-detection/changelog/#v1262), [v1.27.0](https://docs.victoriametrics.com/anomaly-detection/changelog/#v1270). (All models except `isolation_forest_multivariate` class will be dropped) |
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
---
|
||||
weight: 2
|
||||
title: Presets
|
||||
description: "Preconfigured anomaly detection configurations for widely-recognized metrics (e.g., node_exporter)"
|
||||
menu:
|
||||
docs:
|
||||
parent: "anomaly-detection"
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
---
|
||||
weight: 1
|
||||
title: Quick Start
|
||||
description: "Get started with vmanomaly. Install, configure, and run anomaly detection."
|
||||
menu:
|
||||
docs:
|
||||
parent: "anomaly-detection"
|
||||
@@ -137,7 +138,7 @@ Below are the steps to get `vmanomaly` up and running inside a Docker container:
|
||||
1. Pull Docker image:
|
||||
|
||||
```sh
|
||||
docker pull victoriametrics/vmanomaly:v1.30.2
|
||||
docker pull victoriametrics/vmanomaly:v1.30.1
|
||||
```
|
||||
|
||||
2. Create the license file with your license key.
|
||||
@@ -157,7 +158,7 @@ docker run -it \
|
||||
-v ./license:/license \
|
||||
-v ./config.yaml:/config.yaml \
|
||||
-p 8490:8490 \
|
||||
victoriametrics/vmanomaly:v1.30.2 \
|
||||
victoriametrics/vmanomaly:v1.30.1 \
|
||||
/config.yaml \
|
||||
--licenseFile=/license \
|
||||
--loggerLevel=INFO \
|
||||
@@ -174,7 +175,7 @@ docker run -it \
|
||||
-e VMANOMALY_DATA_DUMPS_DIR=/tmp/vmanomaly/data \
|
||||
-e VMANOMALY_MODEL_DUMPS_DIR=/tmp/vmanomaly/models \
|
||||
-p 8490:8490 \
|
||||
victoriametrics/vmanomaly:v1.30.2 \
|
||||
victoriametrics/vmanomaly:v1.30.1 \
|
||||
/config.yaml \
|
||||
--licenseFile=/license \
|
||||
--loggerLevel=INFO \
|
||||
@@ -187,7 +188,7 @@ services:
|
||||
# ...
|
||||
vmanomaly:
|
||||
container_name: vmanomaly
|
||||
image: victoriametrics/vmanomaly:v1.30.2
|
||||
image: victoriametrics/vmanomaly:v1.30.1
|
||||
# ...
|
||||
restart: always
|
||||
volumes:
|
||||
@@ -250,13 +251,12 @@ Before deploying, check the correctness of your configuration validate config fi
|
||||
|
||||
### Example
|
||||
|
||||
Here is an example of a config file that runs the online [Temporal Envelope](https://docs.victoriametrics.com/anomaly-detection/components/models/#temporal-envelope) model on a CPU metric. The scheduler runs inference every five minutes and uses the fit only for initial bootstrap; between fits the model updates causally from each inference batch. The initial fit uses four weeks of data. The model produces `anomaly_score`, `yhat`, `yhat_lower`, and `yhat_upper` [series](https://docs.victoriametrics.com/anomaly-detection/components/models/#vmanomaly-output) for debugging, and its hour-of-day and day-of-week profiles follow the query timezone and daylight-saving-time changes.
|
||||
Here is an example of a config file that runs the online [Temporal Envelope](https://docs.victoriametrics.com/anomaly-detection/components/models/#temporal-envelope) model on a CPU metric. The scheduler runs inference every five minutes and performs a full refit only every 100 weeks; between refits the model updates causally from each inference batch. The initial fit uses four weeks of data. The model produces `anomaly_score`, `yhat`, `yhat_lower`, and `yhat_upper` [series](https://docs.victoriametrics.com/anomaly-detection/components/models/#vmanomaly-output) for debugging, and its hour-of-day and day-of-week profiles follow the query timezone and daylight-saving-time changes.
|
||||
|
||||
```yaml
|
||||
settings:
|
||||
# https://docs.victoriametrics.com/anomaly-detection/components/settings/
|
||||
n_workers: 2 # number of workers to run workload in parallel, set to 0 or negative number to use all available CPU cores
|
||||
native_threads_per_worker: 0 # automatically divide container-aware CPU capacity across workers
|
||||
anomaly_score_outside_data_range: 5.0 # default anomaly score for anomalies outside expected data range
|
||||
restore_state: true # restore state from previous run, available since v1.24.0
|
||||
# https://docs.victoriametrics.com/anomaly-detection/components/settings/#logger-levels
|
||||
@@ -269,12 +269,13 @@ settings:
|
||||
model.online.temporal_envelope: WARNING
|
||||
|
||||
schedulers:
|
||||
online_5m:
|
||||
100w_5m:
|
||||
# https://docs.victoriametrics.com/anomaly-detection/components/scheduler/#periodic-scheduler
|
||||
class: 'periodic'
|
||||
infer_every: '5m'
|
||||
scatter_infer_jobs: true
|
||||
fit_every: '1000d'
|
||||
# Temporal Envelope learns online between full refits.
|
||||
fit_every: '100w'
|
||||
fit_window: '4w'
|
||||
|
||||
models:
|
||||
@@ -282,7 +283,7 @@ models:
|
||||
temporal_envelope_model:
|
||||
class: 'temporal_envelope'
|
||||
queries: ['cpu_user']
|
||||
schedulers: ['online_5m']
|
||||
schedulers: ['100w_5m']
|
||||
provide_series: ['anomaly_score', 'yhat', 'yhat_lower', 'yhat_upper'] # for debugging
|
||||
seasonalities: ['hod_smooth', 'dow_smooth']
|
||||
alpha: 0.005 # trend reactivity; try 0.0025-0.02
|
||||
@@ -297,15 +298,12 @@ reader:
|
||||
tenant_id: '0:0'
|
||||
sampling_period: "5m"
|
||||
tz: 'UTC' # set the IANA timezone that defines local calendar patterns, e.g. 'America/New_York'
|
||||
workers: 0 # automatically choose bounded datasource concurrency
|
||||
series_processing_batch_size: 8 # number of time series to process together while preparing data for fit or infer stages
|
||||
queries:
|
||||
# define your queries with MetricsQL - https://docs.victoriametrics.com/victoriametrics/metricsql/
|
||||
cpu_user:
|
||||
expr: 'sum(rate(node_cpu_seconds_total{mode=~"user"}[10m])) by (container)'
|
||||
data_range: [0, 'inf'] # query-level business policy from v1.30.2
|
||||
detection_direction: 'above_expected' # query-level from v1.30.2; only spikes are anomalous
|
||||
max_points_per_query: 15000 # to deal with longer queries hitting search.maxPointsPerTimeseries
|
||||
max_datapoints_per_query: 15000 # to deal with longer queries hitting search.MaxPointsPerTimeseries
|
||||
# other queries ...
|
||||
|
||||
writer:
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
---
|
||||
weight: 3
|
||||
title: Scaling vmanomaly
|
||||
description: "High availability and horizontal scaling for vmanomaly."
|
||||
menu:
|
||||
docs:
|
||||
identifier: "vmanomaly-scaling"
|
||||
@@ -32,15 +33,14 @@ schedulers:
|
||||
periodic_1d: # alias
|
||||
class: 'periodic' # scheduler class
|
||||
infer_every: "30s"
|
||||
fit_every: "1000d"
|
||||
fit_every: "1h"
|
||||
fit_window: "24h"
|
||||
|
||||
# https://docs.victoriametrics.com/anomaly-detection/components/models/
|
||||
models:
|
||||
zscore: # we can set up alias for model
|
||||
class: 'zscore_online' # online model class
|
||||
class: 'zscore' # model class
|
||||
z_threshold: 3.5
|
||||
decay: 0.99 # give more weight to recent data while using the bootstrap-only fit schedule
|
||||
queries: ['cpu_seconds_total', 'host_network_receive_errors']
|
||||
|
||||
# https://docs.victoriametrics.com/anomaly-detection/components/reader/#vm-reader
|
||||
@@ -81,7 +81,6 @@ Additionally, a replication factor `R ≥ 1` ensures [high availability](#high-a
|
||||
|
||||
{{% content "vmanomaly-sharding-ha-diagram.md" %}}
|
||||
|
||||
> [!WARNING]
|
||||
> Please [refer to deployment options section](#deployment-options) for the examples (Docker, Docker Compose, Helm). To avoid duplicate metrics being reported from each vmanomaly service used in sharded mode, make sure that [deduplication](https://docs.victoriametrics.com/victoriametrics/single-server-victoriametrics/#deduplication) is configured on vmsingle or vmselect and vmstorage for the VictoriaMetrics instance used in the [writer section of the configuration](https://docs.victoriametrics.com/anomaly-detection/components/writer/).
|
||||
|
||||
Sharding configuration can be controlled by using the following environment variables:
|
||||
@@ -89,94 +88,7 @@ Sharding configuration can be controlled by using the following environment vari
|
||||
- **`VMANOMALY_MEMBERS_COUNT`**: Defines the total number of shards (i.e., available nodes to distribute [sub-configurations](#sub-configuration) to). <br>Defaults to `1` for backward compatibility.
|
||||
- **`VMANOMALY_MEMBER_NUM`**: Specifies the shard index (`0` to `VMANOMALY_MEMBERS_COUNT - 1`), determining the subset of [sub-configurations](#sub-configuration) to run on a specific node. Defaults to `0`. Supports automatic **pod name discovery** in Kubernetes [StatefulSets](https://kubernetes.io/docs/concepts/workloads/controllers/statefulset/) (e.g., if set to `vmanomaly-node-exporter-7`, shard `7` will be extracted).
|
||||
- **`VMANOMALY_REPLICATION_FACTOR`**: If `R > 1`, enables [high availability](#high-availability) by ensuring each [sub-configuration](#sub-configuration) is assigned to exactly `R` shards. Defaults to `1` (no replication).
|
||||
- **`VMANOMALY_SPLIT_BY`**: Defines the logical entity used to split the global config into [sub-configurations](#sub-configuration). The accepted values are `SCHEDULERS`, `MODELS`, `QUERIES`, `EXTRA_FILTERS`, and `COMPLETE` (case-insensitive). It defaults to `COMPLETE`, which usually provides the most granular and balanced distribution.
|
||||
|
||||
The split strategies differ as follows:
|
||||
|
||||
| `VMANOMALY_SPLIT_BY` | Unit of work in each sub-configuration | Recommended use |
|
||||
| --- | --- | --- |
|
||||
| `SCHEDULERS` | One scheduler and the workload attached to it | Separate workloads by fit and inference cadence. The number of sub-configurations is limited by the number of referenced schedulers. |
|
||||
| `MODELS` | One configured model alias with its attached schedulers and queries | Isolate computationally different models or distribute several models that process the same queries. |
|
||||
| `QUERIES` | One query for [univariate models](https://docs.victoriametrics.com/anomaly-detection/components/models/#univariate-models); the complete attached query set for each [multivariate model](https://docs.victoriametrics.com/anomaly-detection/components/models/#multivariate-models) | Distribute independent query workloads. Queries belonging to one multivariate model remain together because the model needs all channels. This option does not split the series returned by one query. |
|
||||
| `EXTRA_FILTERS` | One configured `reader.extra_filters` selector, with the full model/query/scheduler topology retained | Partition the series returned by large queries, for example by region, cluster, another stable label, or by [VictoriaMetrics tenant](https://docs.victoriametrics.com/victoriametrics/cluster-victoriametrics/#multitenancy-via-labels) using `vm_account_id` and `vm_project_id` selectors with the multitenant endpoint. The filters must already be defined in the global configuration. |
|
||||
| `COMPLETE` | One valid scheduler/model/query combination; [multivariate](https://docs.victoriametrics.com/anomaly-detection/components/models/#multivariate-models) query sets remain together | Obtain the finest general-purpose split and the default choice for balanced sharding. `reader.extra_filters` are intentionally not expanded by this strategy. |
|
||||
|
||||
After the selected strategy creates the sub-configurations, they are assigned to members in deterministic round-robin order and then replicated according to `VMANOMALY_REPLICATION_FACTOR`.
|
||||
|
||||
### Splitting strategies
|
||||
|
||||
{{% collapse name="Configuration and resulting sub-configurations" %}}
|
||||
|
||||
The following abbreviated global configuration contains two schedulers, two models, four queries, and two data partitions:
|
||||
|
||||
```yaml
|
||||
schedulers:
|
||||
fast:
|
||||
class: periodic
|
||||
infer_every: 1m
|
||||
fit_every: 1000d
|
||||
fit_window: 1d
|
||||
seasonal:
|
||||
class: periodic
|
||||
infer_every: 5m
|
||||
fit_every: 1000d
|
||||
fit_window: 2w
|
||||
|
||||
models:
|
||||
cpu_zscore:
|
||||
class: zscore_online
|
||||
schedulers: [fast]
|
||||
queries: [cpu, error_rate]
|
||||
decay: 0.99
|
||||
gpu_envelope:
|
||||
class: temporal_envelope_multivariate
|
||||
schedulers: [seasonal]
|
||||
queries: [temperature, power]
|
||||
seasonalities: [hod_smooth, dow_smooth]
|
||||
|
||||
reader:
|
||||
class: vm
|
||||
datasource_url: http://victoriametrics:8428/
|
||||
sampling_period: 1m
|
||||
queries:
|
||||
cpu:
|
||||
expr: avg(rate(node_cpu_seconds_total[5m])) by (instance)
|
||||
error_rate:
|
||||
expr: rate(application_errors_total[5m])
|
||||
temperature:
|
||||
expr: avg(gpu_temperature_celsius) by (gpu)
|
||||
power:
|
||||
expr: avg(gpu_power_watts) by (gpu)
|
||||
extra_filters: ['{region="us-east"}', '{region="eu-west"}']
|
||||
|
||||
writer:
|
||||
class: vm
|
||||
datasource_url: http://victoriametrics:8428/
|
||||
```
|
||||
|
||||
For this configuration, each strategy produces the following logical units before they are assigned to shards:
|
||||
|
||||
| Value | Resulting sub-configurations |
|
||||
| --- | --- |
|
||||
| `SCHEDULERS` | `fast`; `seasonal` |
|
||||
| `MODELS` | `cpu_zscore`; `gpu_envelope` |
|
||||
| `QUERIES` | `cpu`; `error_rate`; the multivariate set `power,temperature` |
|
||||
| `EXTRA_FILTERS` | `{region="us-east"}`; `{region="eu-west"}`; each retains all schedulers, models, and queries, while the query context is restricted by its selector |
|
||||
| `COMPLETE` | `fast:cpu_zscore:cpu`; `fast:cpu_zscore:error_rate`; `seasonal:gpu_envelope:power,temperature` |
|
||||
|
||||
For example, choose the query split with:
|
||||
|
||||
```yaml
|
||||
environment:
|
||||
VMANOMALY_MEMBERS_COUNT: 3
|
||||
VMANOMALY_MEMBER_NUM: 0
|
||||
VMANOMALY_REPLICATION_FACTOR: 1
|
||||
VMANOMALY_SPLIT_BY: QUERIES
|
||||
```
|
||||
|
||||
To partition the timeseries returned by the same large query instead, define non-overlapping selectors in `reader.extra_filters` and use `VMANOMALY_SPLIT_BY: EXTRA_FILTERS`. Each generated sub-configuration keeps one selector, for example `{region="us-east"}` or `{region="eu-west"}`.
|
||||
|
||||
{{% /collapse %}}
|
||||
- **`VMANOMALY_SPLIT_BY`**: Defines the logical entity used to split the global config into [sub-configurations](#sub-configuration). Defaults to `complete`, which provides the most granular distribution (1 model per [sub-config](#sub-configuration), mapped to 1 query and attached to 1 scheduler) for balanced workloads.
|
||||
|
||||
---
|
||||
|
||||
@@ -219,7 +131,6 @@ When `VMANOMALY_REPLICATION_FACTOR` > 1, each [sub-config](#sub-configuration) `
|
||||
|
||||
{{% content "vmanomaly-sharding-ha-diagram.md" %}}
|
||||
|
||||
> [!WARNING]
|
||||
> Please [refer to deployment options section](#deployment-options) for the examples (Docker, Docker Compose, Helm). To avoid duplicate metrics being reported from each vmanomaly service used in sharded mode, make sure that [deduplication](https://docs.victoriametrics.com/victoriametrics/single-server-victoriametrics/#deduplication) is configured on vmsingle or vmselect and vmstorage for the VictoriaMetrics instance used in the [writer section of the configuration](https://docs.victoriametrics.com/anomaly-detection/components/writer/).
|
||||
|
||||
### Example
|
||||
@@ -288,11 +199,7 @@ services:
|
||||
user: "1000:1000"
|
||||
restart: always
|
||||
healthcheck:
|
||||
test:
|
||||
- "CMD"
|
||||
- "curl"
|
||||
- "-f"
|
||||
- "http://127.0.0.1:8490/health"
|
||||
test: ["CMD", "curl", "-f", "http://127.0.0.1:8490/health"]
|
||||
interval: 30s
|
||||
timeout: 10s
|
||||
retries: 5
|
||||
@@ -312,11 +219,7 @@ services:
|
||||
user: "1000:1000"
|
||||
restart: always
|
||||
healthcheck:
|
||||
test:
|
||||
- "CMD"
|
||||
- "curl"
|
||||
- "-f"
|
||||
- "http://127.0.0.1:8490/health"
|
||||
test: ["CMD", "curl", "-f", "http://127.0.0.1:8490/health"]
|
||||
interval: 30s
|
||||
timeout: 10s
|
||||
retries: 5
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
---
|
||||
weight: 4
|
||||
title: Self-monitoring
|
||||
description: "Track vmanomaly health and operational performance."
|
||||
menu:
|
||||
docs:
|
||||
identifier: "vmanomaly-self-monitoring"
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
---
|
||||
weight: 2
|
||||
title: UI
|
||||
description: "Built-in vmui-like UI for exploring anomaly detection results."
|
||||
menu:
|
||||
docs:
|
||||
parent: "anomaly-detection"
|
||||
@@ -137,13 +138,13 @@ users:
|
||||
password: '<password>'
|
||||
url_map:
|
||||
- src_hosts:
|
||||
- "metrics.local.some-domain.net"
|
||||
- "metrics.local.some-domain.net"
|
||||
url_prefix: "http://victoriametrics:8428"
|
||||
- src_hosts:
|
||||
- "vl.local.some-domain.net"
|
||||
- "vl.local.some-domain.net"
|
||||
url_prefix: "http://victorialogs:9428"
|
||||
- src_hosts:
|
||||
- "vmanomaly.local.some-domain.net"
|
||||
- "vmanomaly.local.some-domain.net"
|
||||
url_prefix: "http://vmanomaly:8490"
|
||||
keep_original_host: true
|
||||
```
|
||||
@@ -316,7 +317,7 @@ docker run -it --rm \
|
||||
-e VMANOMALY_MCP_SERVER_URL=http://mcp-vmanomaly:8081/mcp \
|
||||
-p 8080:8080 \
|
||||
-p 8490:8490 \
|
||||
victoriametrics/vmanomaly:v1.30.2 \
|
||||
victoriametrics/vmanomaly:v1.30.1 \
|
||||
vmanomaly_config.yaml
|
||||
```
|
||||
|
||||
@@ -645,13 +646,6 @@ If the **results** look good and the **model configuration should be deployed in
|
||||
|
||||
{{% collapse name="Release history" %}}
|
||||
|
||||
### v1.8.2
|
||||
Released: 2026-08-13
|
||||
|
||||
vmanomaly version: [v1.30.2](https://docs.victoriametrics.com/anomaly-detection/changelog/#v1302)
|
||||
|
||||
- BUGFIX: Fixed tenant discovery for VictoriaMetrics datasource URLs containing `/select/multitenant/prometheus`. The UI now loads available numeric tenants from `/admin/tenants` and can switch the datasource URL from `multitenant` to the selected tenant.
|
||||
|
||||
### v1.8.1
|
||||
Released: 2026-08-06
|
||||
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
---
|
||||
title: Anomaly Detection
|
||||
description: "Use vmanomaly to detect anomalies in metrics and logs. Configure models, run inference, monitor the service, and connect results to alerts and dashboards."
|
||||
weight: 50
|
||||
menu:
|
||||
docs:
|
||||
|
||||
@@ -37,7 +37,6 @@ The following minimal configuration demonstrates current many-to-many model, que
|
||||
```yaml
|
||||
settings:
|
||||
n_workers: 4 # number of workers to run models in parallel
|
||||
native_threads_per_worker: 0 # automatically divide container-aware CPU capacity across workers
|
||||
anomaly_score_outside_data_range: 5.0 # default anomaly score for anomalies outside expected data range
|
||||
restore_state: True # restore state from previous run, if available
|
||||
retention: # how long to keep stale models on disk/in memory
|
||||
@@ -51,15 +50,15 @@ schedulers:
|
||||
class: 'periodic' # scheduler class
|
||||
infer_every: "30s" # how often to produce anomaly scores for new data
|
||||
scatter_infer_jobs: true # distribute infer jobs evenly across the infer interval to reduce synchronized bursts
|
||||
fit_every: "1000d" # bootstrap-only schedule; use a finite cadence if accumulated state must be reset
|
||||
fit_every: "365d" # how often to re-fit the models, for online models used effectively once, then they are updated with new data and won't require re-fit
|
||||
fit_window: "3d" # how much historical data to use for fit stage
|
||||
start_from: "00:00" # align the bootstrap fit to midnight in the configured timezone
|
||||
start_from: "00:00" # align the annual fit schedule to midnight in the configured timezone
|
||||
tz: "Europe/Kyiv" # timezone to use for start_from
|
||||
periodic_online_weekly:
|
||||
class: 'periodic'
|
||||
infer_every: "15m"
|
||||
scatter_infer_jobs: true
|
||||
fit_every: "1000d" # bootstrap-only schedule; use a finite cadence if accumulated state must be reset
|
||||
fit_every: "365d" # online state continues adapting between infrequent full re-fits
|
||||
fit_window: "14d"
|
||||
# if no start_from is specified, jobs will start immediately after service starts
|
||||
|
||||
@@ -73,15 +72,17 @@ models:
|
||||
provide_series: ['anomaly_score', 'y', 'yhat', 'yhat_upper'] # what series to produce as output of the model
|
||||
queries: ['host_network_receive_errors'] # what queries to run particular model on
|
||||
schedulers: ['periodic_online'] # will be fit once, used for infer every 30s
|
||||
min_dev_from_expected: 0.0 # turned off. if |y - yhat| < min_dev_from_expected, anomaly score will be 0
|
||||
detection_direction: 'above_expected' # detect anomalies only when y > yhat, "peaks"
|
||||
clip_predictions: True # clip predictions to expected data range, i.e. [0, inf] for this query `host_network_receive_errors
|
||||
envelope_weekly: # we can set up alias for model
|
||||
class: 'temporal_envelope'
|
||||
alpha: 0.005 # adapt the trend while using the bootstrap-only fit schedule
|
||||
loss_reactivity: 3 # allow new deviations to update the envelope
|
||||
provide_series: ['anomaly_score', 'y', 'yhat', 'yhat_lower', 'yhat_upper']
|
||||
queries: ['cpu_seconds_total']
|
||||
schedulers: ['periodic_online_weekly'] # fit on two weekly cycles, then update online every 15m
|
||||
min_dev_from_expected: [0.01, 0.01] # minimum deviation from expected value to be even considered as anomaly
|
||||
anomaly_score_outside_data_range: 1.5 # override default anomaly score outside expected data range
|
||||
detection_direction: 'above_expected'
|
||||
clip_predictions: True # clip predictions to expected data range, i.e. [0, inf] for this query `cpu_seconds_total`
|
||||
seasonalities: ['hod_smooth', 'dow_smooth']
|
||||
|
||||
@@ -92,7 +93,6 @@ reader:
|
||||
datasource_url: "https://play.victoriametrics.com/"
|
||||
tenant_id: "0:0"
|
||||
sampling_period: "30s" # what data resolution to fetch from VictoriaMetrics' /query_range endpoint
|
||||
workers: 0 # automatically choose bounded datasource concurrency
|
||||
latency_offset: '1ms'
|
||||
query_from_last_seen_timestamp: False
|
||||
tz: "UTC" # timezone to use for queries without explicit timezone
|
||||
@@ -101,15 +101,11 @@ reader:
|
||||
cpu_seconds_total:
|
||||
expr: 'avg(rate(node_cpu_seconds_total[5m])) by (mode)'
|
||||
# step: '30s' # if not set, will be equal to reader-level sampling_period
|
||||
data_range: [0, 'inf'] # query-level business policy from v1.30.2
|
||||
detection_direction: 'above_expected' # query-level from v1.30.2; detect spikes only
|
||||
min_dev_from_expected: [0.01, 0.01] # query-level from v1.30.2
|
||||
data_range: [0, 'inf'] # expected value range, anomaly_score = anomaly_score_outside_data_range if y (real value) is outside
|
||||
host_network_receive_errors:
|
||||
expr: 'rate(node_network_receive_errs_total[3m]) / rate(node_network_receive_packets_total[3m])'
|
||||
step: '15m' # here we override per-query `sampling_period` to request way less data from VM TSDB
|
||||
data_range: [0, 'inf'] # query-level business policy from v1.30.2
|
||||
detection_direction: 'above_expected' # query-level from v1.30.2; detect spikes only
|
||||
min_dev_from_expected: 0.0 # query-level from v1.30.2; absolute-deviation filtering is disabled
|
||||
data_range: [0, 'inf']
|
||||
|
||||
# where to write data to
|
||||
# https://docs.victoriametrics.com/anomaly-detection/components/writer/
|
||||
@@ -150,7 +146,7 @@ server:
|
||||
|
||||
{{% available_from "v1.25.0" anomaly %}} The service supports hot reload of configuration files, applying changes without an explicit restart. Enable it with the `--watch` [CLI argument](https://docs.victoriametrics.com/anomaly-detection/quickstart/#command-line-arguments). The `vmanomaly_config_reload_enabled` [self-monitoring metric](https://docs.victoriametrics.com/anomaly-detection/components/monitoring/#startup-metrics) is `1` when hot reload is enabled and `0` otherwise.
|
||||
|
||||
> [!WARNING]
|
||||
> [!NOTE]
|
||||
> {{% deprecated_from "v1.29.5" anomaly %}} File system event-based hot reload has been deprecated in favor of content-based polling with configurable `-configCheckInterval` due to reliability issues with Kubernetes ConfigMap symlink rotations and other filesystems where event delivery can be inconsistent. If you were using file system event-based hot reload, please switch to content-based polling by enabling `--watch` flag and configuring `-configCheckInterval` as needed.
|
||||
|
||||
### How it works
|
||||
@@ -177,7 +173,7 @@ schedulers:
|
||||
periodic:
|
||||
class: 'periodic'
|
||||
infer_every: "30s"
|
||||
fit_every: "1000d" # bootstrap-only schedule; use a finite cadence if accumulated state must be reset
|
||||
fit_every: "365d"
|
||||
fit_window: "24h"
|
||||
|
||||
reader:
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
---
|
||||
title: Components
|
||||
description: "Architecture overview. Models, reader, writer, scheduler, monitoring, settings, server."
|
||||
weight: 3
|
||||
menu:
|
||||
docs:
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
---
|
||||
title: Models
|
||||
description: "Model types and configuration. Built-in and custom anomaly detection models."
|
||||
weight: 1
|
||||
menu:
|
||||
docs:
|
||||
@@ -65,9 +66,6 @@ models:
|
||||
|
||||
Common arguments supported by every model were introduced in [v1.10.0](https://docs.victoriametrics.com/anomaly-detection/changelog/#v1100).
|
||||
|
||||
> [!WARNING]
|
||||
> Configuring `data_range`, `detection_direction`, `min_dev_from_expected`, or `min_rel_dev_from_expected` at model level is deprecated {{% deprecated_from "v1.30.2" anomaly %}}. These stable KPI policies belong under [`reader.queries.<alias>`](https://docs.victoriametrics.com/anomaly-detection/components/reader/#per-query-parameters), where they remain consistent across every [univariate](#univariate-models) or [multivariate](#multivariate-models) model that uses the query. Existing model-level values remain compatible as model-local fallbacks when an attached query does not define the corresponding field; an explicit query value is authoritative.
|
||||
|
||||
<div class="collapse-group">
|
||||
|
||||
{{% collapse name="Queries" %}}
|
||||
@@ -148,46 +146,61 @@ models:
|
||||
{{% collapse name="Detection direction" %}}
|
||||
|
||||
### Detection direction
|
||||
The `detection_direction` argument{{% available_from "v1.13.0" anomaly %}} can reduce [false positives](https://victoriametrics.com/blog/victoriametrics-anomaly-detection-handbook-chapter-1/#false-positive) when domain knowledge indicates that only values above or below the expected value are anomalous. Available values are `both`, `above_expected`, and `below_expected`. Configure it on the input query; model-level placement is {{% deprecated_from "v1.30.2" anomaly %}}.
|
||||
The `detection_direction` argument{{% available_from "v1.13.0" anomaly %}} can reduce [false positives](https://victoriametrics.com/blog/victoriametrics-anomaly-detection-handbook-chapter-1/#false-positive) when domain knowledge indicates that only values above or below the expected value are anomalous. Available values are `both`, `above_expected`, and `below_expected`.
|
||||
|
||||
Here's how the three options differ:
|
||||
Here's how default (backward-compatible) behavior looks like - anomalies will be tracked in `both` directions (`y > yhat` or `y < yhat`). This is useful when there is no domain expertise to filter the required direction.
|
||||
|
||||

|
||||

|
||||
|
||||
With the default, backward-compatible `both` value, anomalies are tracked in both directions (`y > yhat` or `y < yhat`). This is useful when there is no domain expertise to filter the required direction.
|
||||
|
||||
When set to `above_expected`, anomalies are tracked only when `y > yhat`.
|
||||
|
||||
*Example metrics*: Error rate, response time, page load time, number of failed transactions - metrics where *lower values are better*, so **higher** values are typically tracked.
|
||||
|
||||

|
||||
|
||||
|
||||
When set to `below_expected`, anomalies are tracked only when `y < yhat`.
|
||||
|
||||
*Example metrics*: Service Level Agreement (SLA) compliance, conversion rate, Customer Satisfaction Score (CSAT) - metrics where *higher values are better*, so **lower** values are typically tracked.
|
||||
|
||||
One model can use multiple queries with different directions because the policy belongs to each query:
|
||||

|
||||
|
||||
|
||||
Config with a split example:
|
||||
|
||||
```yaml
|
||||
models:
|
||||
model_above_expected:
|
||||
class: 'zscore_online'
|
||||
z_threshold: 3.0
|
||||
# track only cases when y > yhat, otherwise anomaly_score would be explicitly set to 0
|
||||
detection_direction: 'above_expected'
|
||||
# for this query we do not need to track lower values, thus, set anomaly detection tracking for y > yhat (above_expected)
|
||||
queries: ['query_values_the_lower_the_better']
|
||||
model_below_expected:
|
||||
class: 'zscore_online'
|
||||
z_threshold: 3.0
|
||||
# track only cases when y < yhat, otherwise anomaly_score would be explicitly set to 0
|
||||
detection_direction: 'below_expected'
|
||||
# for this query we do not need to track higher values, thus, set anomaly detection tracking for y < yhat (above_expected)
|
||||
queries: ['query_values_the_higher_the_better']
|
||||
model_bidirectional_default:
|
||||
class: 'zscore_online'
|
||||
z_threshold: 3.0
|
||||
# track in both direction, same backward-compatible behavior in case this arg is missing
|
||||
detection_direction: 'both'
|
||||
# for this query both directions can be equally important for anomaly detection, thus, setting it bidirectional (both)
|
||||
queries: ['query_values_both_direction_matters']
|
||||
reader:
|
||||
# ...
|
||||
queries:
|
||||
query_values_the_lower_the_better:
|
||||
query_values_the_lower_the_better:
|
||||
expr: metricsql_expression1
|
||||
detection_direction: 'above_expected' # query-level from v1.30.2; only y > yhat can be anomalous
|
||||
query_values_the_higher_the_better:
|
||||
query_values_the_higher_the_better:
|
||||
expr: metricsql_expression2
|
||||
detection_direction: 'below_expected' # query-level from v1.30.2; only y < yhat can be anomalous
|
||||
query_values_both_direction_matters:
|
||||
query_values_both_direction_matters:
|
||||
expr: metricsql_expression3
|
||||
detection_direction: 'both' # query-level from v1.30.2; the default when omitted
|
||||
models:
|
||||
model_all_directions:
|
||||
class: 'zscore_online'
|
||||
z_threshold: 3.0
|
||||
queries: [
|
||||
'query_values_the_lower_the_better',
|
||||
'query_values_the_higher_the_better',
|
||||
'query_values_both_direction_matters',
|
||||
]
|
||||
# other components like writer, schedule, monitoring
|
||||
```
|
||||
|
||||
@@ -197,7 +210,7 @@ models:
|
||||
|
||||
### Minimal deviation from expected
|
||||
|
||||
`min_dev_from_expected`{{% available_from "v1.13.0" anomaly %}} argument is designed to **reduce [false positives](https://victoriametrics.com/blog/victoriametrics-anomaly-detection-handbook-chapter-1/#false-positive)** in scenarios where deviations between the actual value (`y`) and the expected value (`yhat`) are **relatively** high. Such deviations can cause models to generate high [anomaly scores](https://docs.victoriametrics.com/anomaly-detection/faq/#what-is-anomaly-score). However, these deviations may not be significant enough in **absolute values** from a business perspective to be considered anomalies. This parameter ensures that anomaly scores for data points where `|y - yhat| < min_dev_from_expected` are explicitly set to 0. By default, if this parameter is not set, it is set to `0` to maintain backward compatibility. Configure it on the input query; model-level placement is {{% deprecated_from "v1.30.2" anomaly %}}.
|
||||
`min_dev_from_expected`{{% available_from "v1.13.0" anomaly %}} argument is designed to **reduce [false positives](https://victoriametrics.com/blog/victoriametrics-anomaly-detection-handbook-chapter-1/#false-positive)** in scenarios where deviations between the actual value (`y`) and the expected value (`yhat`) are **relatively** high. Such deviations can cause models to generate high [anomaly scores](https://docs.victoriametrics.com/anomaly-detection/faq/#what-is-anomaly-score). However, these deviations may not be significant enough in **absolute values** from a business perspective to be considered anomalies. This parameter ensures that anomaly scores for data points where `|y - yhat| < min_dev_from_expected` are explicitly set to 0. By default, if this parameter is not set, it is set to `0` to maintain backward compatibility.
|
||||
|
||||
> [!NOTE]
|
||||
{{% available_from "v1.23.0" anomaly %}} The `min_dev_from_expected` argument can be a list of two float values, allowing separate thresholds for upper and lower deviations. This is useful when the acceptable deviation varies in different directions (e.g., `min_dev_from_expected: [0.01, 0.02]` means that the lower bound is `0.01` when `y` is less than `yhat` and the upper bound is `0.02` when `y` is greater than `yhat`). If only one value is provided, it is broadcasted to both directions, meaning that the same threshold is applied for both upper and lower deviations (e.g., `min_dev_from_expected: 0.01` means that the lower bound is `0.01` when `y` is less than `yhat` and the upper bound is also `0.01` when `y` is greater than `yhat`).
|
||||
@@ -206,9 +219,15 @@ models:
|
||||
|
||||
*Example*: Consider a scenario where CPU utilization in specific mode is low and oscillates around 0.3% (0.003). A sudden spike to 1.3% (0.013) represents a +333% increase in **relative** terms, but only a +1 percentage point (0.01) increase in **absolute** terms, which may be negligible and not warrant an alert. Setting the `min_dev_from_expected` argument to `0.01` (1%) will ensure that all anomaly scores for deviations <= `0.01` are set to 0.
|
||||
|
||||
The visualization below demonstrates this concept. The narrow blue model prediction boundary is nested inside the wider green business protection boundary. Actual values outside the prediction boundary but still within `[yhat - min_dev_from_expected, yhat + min_dev_from_expected]` receive `anomaly_score = 0`; only values outside the green boundary remain anomalous.
|
||||
Visualizations below demonstrate this concept; the green zone defined as the `[yhat - min_dev_from_expected, yhat + min_dev_from_expected]` range excludes actual data points (`y`) from generating anomaly scores if they fall within that range.
|
||||
|
||||

|
||||

|
||||
|
||||
|
||||

|
||||
|
||||
|
||||

|
||||
|
||||
Example config of how to use this param based on query results:
|
||||
|
||||
@@ -218,17 +237,23 @@ reader:
|
||||
# ...
|
||||
queries:
|
||||
# the usage of min_dev should reduce false positives here
|
||||
need_to_include_min_dev:
|
||||
need_to_include_min_dev:
|
||||
expr: small_abs_values_metricsql_expression
|
||||
min_dev_from_expected: [5.0, 5.0] # query-level from v1.30.2
|
||||
# min_dev is not really needed here
|
||||
normal_behavior:
|
||||
normal_behavior:
|
||||
expr: no_need_to_exclude_small_deviations_metricsql_expression
|
||||
models:
|
||||
zscore:
|
||||
zscore_with_min_dev:
|
||||
class: 'zscore_online'
|
||||
z_threshold: 3
|
||||
queries: ['need_to_include_min_dev', 'normal_behavior']
|
||||
min_dev_from_expected: [5.0, 5.0] # set the same threshold for both directions, meaning that deviations less than 5.0 in absolute values won't be considered anomalous, even if they are relatively significant
|
||||
queries: ['need_to_include_min_dev'] # use such models on queries where domain experience confirm usefulness
|
||||
zscore_wo_min_dev:
|
||||
class: 'zscore_online'
|
||||
z_threshold: 3
|
||||
# if not set, equals to setting min_dev_from_expected == 0 (meaning no filtering is applied)
|
||||
# min_dev_from_expected: [0.0, 0.0]
|
||||
queries: ['normal_behavior'] # use the default where it's not needed
|
||||
```
|
||||
|
||||
{{% /collapse %}}
|
||||
@@ -237,17 +262,13 @@ models:
|
||||
|
||||
### Minimal relative deviation from expected
|
||||
|
||||
{{% available_from "v1.29.1" anomaly %}} `min_rel_dev_from_expected` argument serves a similar purpose to `min_dev_from_expected` (see [section above](#minimal-deviation-from-expected)), but focuses on **relative deviations** rather than absolute ones. It is designed to reduce [false positives](https://victoriametrics.com/blog/victoriametrics-anomaly-detection-handbook-chapter-1/#false-positive) in scenarios where the relative deviation between the actual value (`y`) and the expected value (`yhat`) is high, but the absolute deviation is not significant enough to be considered an anomaly from a business perspective. This parameter ensures that anomaly scores for data points where `|y - yhat| / |yhat| < min_rel_dev_from_expected` are explicitly set to 0. By default, if this parameter is not set, it is set to `0` to maintain backward compatibility. Configure it on the input query; model-level placement is {{% deprecated_from "v1.30.2" anomaly %}}.
|
||||
{{% available_from "v1.29.1" anomaly %}} `min_rel_dev_from_expected` argument serves a similar purpose to `min_dev_from_expected` (see [section above](#minimal-deviation-from-expected)), but focuses on **relative deviations** rather than absolute ones. It is designed to reduce [false positives](https://victoriametrics.com/blog/victoriametrics-anomaly-detection-handbook-chapter-1/#false-positive) in scenarios where the relative deviation between the actual value (`y`) and the expected value (`yhat`) is high, but the absolute deviation is not significant enough to be considered an anomaly from a business perspective. This parameter ensures that anomaly scores for data points where `|y - yhat| / |yhat| < min_rel_dev_from_expected` are explicitly set to 0. By default, if this parameter is not set, it is set to `0` to maintain backward compatibility.
|
||||
|
||||
Parameter can be a list of two float values, *allowing separate thresholds for upper and lower relative deviations*. If only one value is provided, it is broadcasted to both directions.
|
||||
|
||||
> [!NOTE]
|
||||
If both `min_dev_from_expected` [arg](#minimal-deviation-from-expected) and `min_rel_dev_from_expected` are set, the model will combine both filters. A data point will be considered anomalous (i.e., have an anomaly score != 0) only if it exceeds **both** the *absolute* deviation threshold defined by `min_dev_from_expected` and the *relative* deviation threshold defined by `min_rel_dev_from_expected`. This allows for more granular control over anomaly detection, ensuring that only significant deviations in both absolute and relative terms are flagged as anomalies.
|
||||
|
||||
The green business protection boundary below scales with `|yhat|`, while the model prediction boundary remains visible inside it. Actual values outside the blue boundary but inside the proportional green boundary receive `anomaly_score = 0`.
|
||||
|
||||

|
||||
|
||||
|
||||
*Example*: Consider a scenario of monitoring incoming traffic to websites that typically receives *unknown in advance* requests per second (from tens to thousands). Setting absolute deviation threshold with `min_dev_from_expected` *may not be effective in reducing false positives*, as even a small increase in traffic (e.g., from 10 to 20 requests per second) can represent a 100% relative increase, which may be significant for that website. Instead, setting `min_rel_dev_from_expected` to smaller relative value - `[20, 40]` (20/40%) - will ensure that traffic drop from 10 to 8 requests per second (20% decrease) and traffic spike from 10 to 14 requests per second (40% increase) won't be considered anomalous, even if they exceed confidence intervals, thus, reducing false positives for small absolute deviations that are relatively significant.
|
||||
|
||||
@@ -259,17 +280,23 @@ reader:
|
||||
# ...
|
||||
queries:
|
||||
# the usage of min_rel_dev should reduce false positives here
|
||||
need_to_include_min_rel_dev:
|
||||
need_to_include_min_rel_dev:
|
||||
expr: small_abs_values_metricsql_expression
|
||||
min_rel_dev_from_expected: [10, 20] # query-level from v1.30.2
|
||||
# min_rel_dev is not really needed here
|
||||
normal_behavior:
|
||||
normal_behavior:
|
||||
expr: no_need_to_exclude_small_deviations_metricsql_expression
|
||||
models:
|
||||
zscore:
|
||||
zscore_with_min_rel_dev:
|
||||
class: 'zscore_online'
|
||||
z_threshold: 3
|
||||
queries: ['need_to_include_min_rel_dev', 'normal_behavior']
|
||||
min_rel_dev_from_expected: [10, 20] # set different thresholds for both directions, meaning that relative deviations less than 10% when y < yhat and less than 20% when y > yhat won't be considered anomalous, even if they exceed confidence intervals, thus, reducing false positives for small absolute deviations that are relatively significant
|
||||
queries: ['need_to_include_min_rel_dev'] # use such models on queries where domain experience confirm usefulness
|
||||
zscore_wo_min_rel_dev:
|
||||
class: 'zscore_online'
|
||||
z_threshold: 3
|
||||
# if not set, equals to setting min_rel_dev_from_expected == 0 (meaning no filtering is applied)
|
||||
# min_rel_dev_from_expected: [0, 0]
|
||||
queries: ['normal_behavior'] # use the default where it's not needed
|
||||
```
|
||||
|
||||
|
||||
@@ -292,29 +319,17 @@ reader:
|
||||
# assume there are M unique hosts identified by the `host` label
|
||||
queries:
|
||||
# return one timeseries for each CPU mode per host, total = N*M timeseries
|
||||
cpu:
|
||||
expr: sum(rate(node_cpu_seconds_total[5m])) by (host, mode)
|
||||
data_range: [0, 'inf']
|
||||
detection_direction: both
|
||||
min_rel_dev_from_expected: [15, 15]
|
||||
cpu: sum(rate(node_cpu_seconds_total[5m])) by (host, mode)
|
||||
# return one timeseries per host, total = 1*M timeseries
|
||||
ram:
|
||||
expr: |
|
||||
100 * (
|
||||
1 - node_memory_MemAvailable_bytes
|
||||
/ node_memory_MemTotal_bytes
|
||||
)
|
||||
data_range: [0, 100]
|
||||
detection_direction: above_expected
|
||||
min_rel_dev_from_expected: [0, 15]
|
||||
ram: |
|
||||
(
|
||||
(node_memory_MemTotal_bytes - node_memory_MemAvailable_bytes)
|
||||
/ node_memory_MemTotal_bytes
|
||||
) * 100 by (host)
|
||||
# return one timeseries per host for both network receive and transmit data, total = 1*M timeseries
|
||||
network:
|
||||
expr: |
|
||||
sum(rate(node_network_receive_bytes_total[5m])) by (host)
|
||||
+ sum(rate(node_network_transmit_bytes_total[5m])) by (host)
|
||||
data_range: [0, 'inf']
|
||||
detection_direction: below_expected
|
||||
min_rel_dev_from_expected: [20, 0]
|
||||
network: |
|
||||
sum(rate(node_network_receive_bytes_total[5m])) by (host)
|
||||
+ sum(rate(node_network_transmit_bytes_total[5m])) by (host)
|
||||
|
||||
models:
|
||||
envelope: # alias for the model
|
||||
@@ -328,9 +343,6 @@ models:
|
||||
groupby: [host]
|
||||
```
|
||||
|
||||
> [!TIP]
|
||||
> {{% available_from "v1.30.2" anomaly %}} Multivariate Temporal Envelope applies each query's [`data_range`, `detection_direction`, and minimum relative deviation](https://docs.victoriametrics.com/anomaly-detection/components/reader/#per-query-parameters) to every channel returned by that query before aggregating the joint anomaly score. The example detects CPU deviations in either direction, RAM increases of at least 15%, and network drops of at least 20% within each host model.
|
||||
|
||||
{{% /collapse %}}
|
||||
|
||||
{{% collapse name="Scale" %}}
|
||||
@@ -348,10 +360,6 @@ For example, setting `scale: [1.2, 0.75]` for particular model will:
|
||||
- **Increase** the width of the lower confidence interval by **20%**.
|
||||
- **Decrease** the width of the upper confidence boundary by **25%**.
|
||||
|
||||
Alternative visualization:
|
||||
|
||||

|
||||
|
||||
The most common **use case** is when there is a preference to **widen one side** to blacklist smaller false positives (which otherwise would have [anomaly scores](https://docs.victoriametrics.com/anomaly-detection/faq/#how-is-anomaly-score-calculated) **only slightly higher than 1.0**, still making such data points **anomalous**), while **tightening the other side** to avoid missing true positives due to an overly loose margin (leading to [anomaly scores](https://docs.victoriametrics.com/anomaly-detection/faq/#how-is-anomaly-score-calculated) being slightly less than 1.0, making such data points **non-anomalous**).
|
||||
|
||||
```yaml
|
||||
@@ -550,8 +558,6 @@ For a multivariate model, **one shared model instance** is fitted and used acros
|
||||
|
||||
For example, if you have some **multivariate** model to use 3 [MetricQL queries](https://docs.victoriametrics.com/victoriametrics/metricsql/), each returning 5 time series, there will be one shared model created in total. Once fit, this model will expect **exactly 15 time series with exact same labelsets as an input**. This model will produce **one shared [output](#vmanomaly-output)**.
|
||||
|
||||
> {{% available_from "v1.30.2" anomaly %}} Multivariate Temporal Envelope and Isolation Forest accept matching input channels in any order. The channel set must still match the fitted model exactly: missing, extra, and duplicate channels are rejected, while a matching set is restored to learned fit order before inference or online updates.
|
||||
|
||||
> {{% available_from "v1.16.0" anomaly %}} N models — one for each N unique combinations of label values specified in the `groupby` [common argument](#group-by) — can be trained. This allows for context separation (e.g., one model per host, region, or other relevant grouping label), leading to improved accuracy and faster training. See an example [here](#group-by).
|
||||
|
||||
If during an inference, you got a **different amount of series** or some series having a **new labelset** (not present in any of fitted models), the inference will be skipped until you get a model, trained particularly for such labelset during forthcoming re-fit step.
|
||||
@@ -680,7 +686,7 @@ Selecting model [hyperparameters](https://en.wikipedia.org/wiki/Hyperparameter_(
|
||||
- `tuned_class_name` (string) - [Built-in model class](#built-in-models) to wrap, i.e. `zscore_online`
|
||||
- `optimization_params` (dict) - Optimization parameters for *unsupervised* model tuning. Control percentage of found anomalies, as well as a tradeoff between time spent and the accuracy. The higher `timeout` and `n_trials` are, the better model configuration can be found for `tuned_class_name`, but the longer it takes and vice versa. Set `n_jobs` to `-1` to use all the CPUs available, it makes sense if only you have a big dataset to train on during `fit` calls, otherwise overhead isn't worth it.
|
||||
- `anomaly_percentage` (float) - Expected percentage of anomalies that can be seen in training data, from `[0, 0.5)` interval (i.e. 0.01 means it's expected ~ 1% of anomalies to be present in training data). This is a *required* parameter.
|
||||
- `optimized_business_params` (list[string]) - {{% available_from "v1.15.0" anomaly %}} Experimental optimization of model-level business parameters is {{% deprecated_from "v1.30.2" anomaly %}}. Keep this list empty and configure stable `detection_direction`, `min_dev_from_expected`, and `min_rel_dev_from_expected` policies on [`reader.queries.<alias>`](https://docs.victoriametrics.com/anomaly-detection/components/reader/#per-query-parameters) instead.
|
||||
- `optimized_business_params` (list[string]) - {{% available_from "v1.15.0" anomaly %}} this argument allows particular [business-specific parameters](#common-args) such as [`detection_direction`](https://docs.victoriametrics.com/anomaly-detection/components/models/#detection-direction) or [`min_dev_from_expected`](https://docs.victoriametrics.com/anomaly-detection/components/models/#minimal-deviation-from-expected) to remain **unchanged during optimizations, retaining their initial values**. I.e. setting `optimized_business_params` to `['detection_direction']` will allow to optimize only `detection_direction` business-specific arg, while `min_dev_from_expected` will retain its default value of (e.g. [1, 2] if set to that value in model config). By default and if not set, will be equal to `[]` (empty list), meaning no business params will be optimized. **A recommended option is to leave it empty** as this feature is still experimental and may lead to unexpected results.
|
||||
- `seed` (int) - Random seed for reproducibility and deterministic nature of underlying optimizations.
|
||||
- `validation_scheme` (string) - {{% available_from "v1.25.1" anomaly %}} the validation scheme to use for hyperparameter tuning, either `regular` (time-based default) or `leaky` (regular cross-validation with `n_splits` folds, where each fold is a time-based split of the data). The `leaky` scheme is recommended for `anomaly_percentage` ~ 0%, as it allows the model to "see" all the datapoints at least once during the optimization process, which can lead to better results in such cases. Defaults to `regular`.
|
||||
- `n_splits` (int) - How many folds to create for hyperparameter tuning out of your data. The higher, the longer it takes but the better the results can be. Defaults to 3.
|
||||
@@ -804,7 +810,7 @@ For simple profiles without strong trend or seasonality, prefer [Online MAD](#on
|
||||
|
||||
Preset suffixes describe expected profile shape: `smooth` represents gradual recurring curves, `spiky` represents narrow phase peaks, and `plateau` represents sustained calendar levels. Choose only profiles supported by the data. Calendar and holiday features use civil time from the configured query timezone, so hour/day profiles remain aligned across daylight-saving-time transitions.
|
||||
|
||||
Temporal Envelope also supports the [common model arguments](#common-args), including `queries`, `schedulers`, `provide_series`, `scale`, and `clip_predictions`. Configure `data_range`, `detection_direction`, `min_dev_from_expected`, `min_rel_dev_from_expected`, and query timezone under the corresponding [reader query](https://docs.victoriametrics.com/anomaly-detection/components/reader/#per-query-parameters). The multivariate variant applies these business policies independently to each input channel {{% available_from "v1.30.2" anomaly %}}, so one model can represent combinations such as temperature above expected, power above expected, and clock below expected.
|
||||
Temporal Envelope also supports the [common model arguments](#common-args), including `queries`, `schedulers`, `provide_series`, `detection_direction`, `scale`, `clip_predictions`, `min_dev_from_expected`, and `min_rel_dev_from_expected`. Input `data_range` and query timezone are configured on the [reader](https://docs.victoriametrics.com/anomaly-detection/components/reader/#config-parameters).
|
||||
|
||||
The multivariate variant uses `class: temporal_envelope_multivariate` or `model.online.TemporalEnvelopeMultivariateModel` and adds:
|
||||
|
||||
@@ -895,13 +901,10 @@ models:
|
||||
# See https://docs.victoriametrics.com/anomaly-detection/components/models/#common-args
|
||||
#
|
||||
# provide_series: ['anomaly_score', 'yhat', 'yhat_lower', 'yhat_upper']
|
||||
# schedulers: [
|
||||
# all scheduler aliases defined in `scheduler` section,
|
||||
# ]
|
||||
# queries: [
|
||||
# all query aliases defined in `reader.queries` section,
|
||||
# ]
|
||||
# Configure detection_direction and minimum-deviation policies under reader.queries.<alias> (query-level from v1.30.2).
|
||||
# schedulers: [all scheduler aliases defined in `scheduler` section]
|
||||
# queries: [all query aliases defined in `reader.queries` section]
|
||||
# detection_direction: 'both' # meaning both drops and spikes will be captured
|
||||
# min_dev_from_expected: [0.0, 0.0] # meaning, no minimal threshold is applied to prevent smaller anomalies
|
||||
# scale: [1.0, 1.0] # if needed, prediction intervals' width can be increased (>1) or narrowed (<1)
|
||||
# clip_predictions: False # if data_range for respective `queries` is set in reader, `yhat.*` columns will be clipped
|
||||
# anomaly_score_outside_data_range: 1.01 # auto anomaly score (1.01) if `y` (real value) is outside of data_range, if set
|
||||
@@ -965,13 +968,10 @@ models:
|
||||
# See https://docs.victoriametrics.com/anomaly-detection/components/models/#common-args
|
||||
#
|
||||
# provide_series: ['anomaly_score', 'yhat', 'yhat_lower', 'yhat_upper']
|
||||
# schedulers: [
|
||||
# all scheduler aliases defined in `scheduler` section,
|
||||
# ]
|
||||
# queries: [
|
||||
# all query aliases defined in `reader.queries` section,
|
||||
# ]
|
||||
# Configure detection_direction and minimum-deviation policies under reader.queries.<alias> (query-level from v1.30.2).
|
||||
# schedulers: [all scheduler aliases defined in `scheduler` section]
|
||||
# queries: [all query aliases defined in `reader.queries` section]
|
||||
# detection_direction: 'both' # meaning both drops and spikes will be captured
|
||||
# min_dev_from_expected: [0.0, 0.0] # meaning, no minimal threshold is applied to prevent smaller anomalies
|
||||
# scale: [1.0, 1.0] # if needed, prediction intervals' width can be increased (>1) or narrowed (<1)
|
||||
# clip_predictions: False # if data_range for respective `queries` is set in reader, `yhat.*` columns will be clipped
|
||||
# anomaly_score_outside_data_range: 1.01 # auto anomaly score (1.01) if `y` (real value) is outside of data_range, if set
|
||||
@@ -1015,13 +1015,10 @@ models:
|
||||
# See https://docs.victoriametrics.com/anomaly-detection/components/models/#common-args
|
||||
#
|
||||
# provide_series: ['anomaly_score', 'yhat', 'yhat_lower', 'yhat_upper']
|
||||
# schedulers: [
|
||||
# all scheduler aliases defined in `scheduler` section,
|
||||
# ]
|
||||
# queries: [
|
||||
# all query aliases defined in `reader.queries` section,
|
||||
# ]
|
||||
# Configure detection_direction and minimum-deviation policies under reader.queries.<alias> (query-level from v1.30.2).
|
||||
# schedulers: [all scheduler aliases defined in `scheduler` section]
|
||||
# queries: [all query aliases defined in `reader.queries` section]
|
||||
# detection_direction: 'both' # meaning both drops and spikes will be captured
|
||||
# min_dev_from_expected: [0.0, 0.0] # meaning, no minimal threshold is applied to prevent smaller anomalies
|
||||
# scale: [1.0, 1.0] # if needed, prediction intervals' width can be increased (>1) or narrowed (<1)
|
||||
# clip_predictions: False # if data_range for respective `queries` is set in reader, `yhat.*` columns will be clipped
|
||||
# anomaly_score_outside_data_range: 1.01 # auto anomaly score (1.01) if `y` (real value) is outside of data_range, if set
|
||||
@@ -1064,13 +1061,10 @@ models:
|
||||
# See https://docs.victoriametrics.com/anomaly-detection/components/models/#common-args
|
||||
#
|
||||
# provide_series: ['anomaly_score', 'yhat', 'yhat_lower', 'yhat_upper']
|
||||
# schedulers: [
|
||||
# all scheduler aliases defined in `scheduler` section,
|
||||
# ]
|
||||
# queries: [
|
||||
# all query aliases defined in `reader.queries` section,
|
||||
# ]
|
||||
# Configure detection_direction and minimum-deviation policies under reader.queries.<alias> (query-level from v1.30.2).
|
||||
# schedulers: [all scheduler aliases defined in `scheduler` section]
|
||||
# queries: [all query aliases defined in `reader.queries` section]
|
||||
# detection_direction: 'both' # meaning both drops and spikes will be captured
|
||||
# min_dev_from_expected: [0.0, 0.0] # meaning, no minimal threshold is applied to prevent smaller anomalies
|
||||
# scale: [1.0, 1.0] # if needed, prediction intervals' width can be increased (>1) or narrowed (<1)
|
||||
# clip_predictions: False # if data_range for respective `queries` is set in reader, `yhat.*` columns will be clipped
|
||||
# anomaly_score_outside_data_range: 1.01 # auto anomaly score (1.01) if `y` (real value) is outside of data_range, if set
|
||||
@@ -1106,7 +1100,6 @@ Resulting metrics of the model are described [here](#vmanomaly-output).
|
||||
- `tz_use_cyclical_encoding`{{% available_from "v1.18.0" anomaly %}} (bool): If set to `True`, applies [cyclical encoding technique](https://www.kaggle.com/code/avanwyk/encoding-cyclical-features-for-deep-learning) to timezone-aware seasonalities. Should be used with `tz_aware=True` and `tz_seasonalities`.
|
||||
- `forecast_at`{{% available_from "v1.25.3" anomaly %}} (list[str]): Specifies future relative offsets for which forecasts should be generated (e.g., `['1h', '1d']`). Works similarly to [predict_linear](https://docs.victoriametrics.com/victoriametrics/metricsql/#predict_linear) in MetricQL, but with more flexibility and seasonality support - produced series will have *the same timestamp* as the other [output](#vmanomaly-output) series, but with the forecasted value for the *future timestamp*. Defaults to `[]` (empty list, meaning no future forecasts are produced). If set, `provide_series` must include at least `yhat` for point-wise forecasts (and `yhat_lower` or/and `yhat_upper` for respective confidence intervals). For example, if `forecast_at` is set to `['1h', '1d']`, the model will produce forecasts for both the next hour and the next day, and these series can be accessed by `yhat_1h`, `yhat_lower_1h`, `yhat_upper_1h`, `yhat_1d`, `yhat_lower_1d`, and `yhat_upper_1d` in the output, respectively. See [FAQ](https://docs.victoriametrics.com/anomaly-detection/faq/#forecasting) for more details.
|
||||
|
||||
> [!WARNING]
|
||||
> `forecast_at` parameter can lead to **significant increase in active timeseries** if you have a lot of time series returned by your queries, as it will produce additional series for each of the future timestamps specified in `forecast_at` (optionally multiplied by 1-3 if interval forecasts are included). For example, if you have 1000 time series returned by your query and set `forecast_at` to `[1h, 1d, 1w]`, and `provide_series` includes `yhat_lower` and `yhat_upper`, it will produce 1000 (series) * 3 (intervals) * 3 (predictions, point + interval) = 9000 additional timeseries. Consider using it only on small subset of metrics (e.g. grouped by `host` or `region`) to avoid this issue, as it also **proportionally (to the number of `forecast_at` elements) increases the timings of inference calls**.
|
||||
|
||||
- `compression` {{% available_from "v1.28.1" anomaly %}} (dict, optional): Configuration for downsampling input data before fitting the model. Useful for high-frequency data to reduce CPU and RAM/disk load and improve model performance. The `compression` block supports the following parameters:
|
||||
@@ -1129,13 +1122,10 @@ models:
|
||||
# See https://docs.victoriametrics.com/anomaly-detection/components/models/#common-args
|
||||
#
|
||||
# provide_series: ['anomaly_score', 'yhat', 'yhat_lower', 'yhat_upper', 'trend']
|
||||
# schedulers: [
|
||||
# all scheduler aliases defined in `scheduler` section,
|
||||
# ]
|
||||
# queries: [
|
||||
# all query aliases defined in `reader.queries` section,
|
||||
# ]
|
||||
# Configure detection_direction and minimum-deviation policies under reader.queries.<alias> (query-level from v1.30.2).
|
||||
# schedulers: [all scheduler aliases defined in `scheduler` section]
|
||||
# queries: [all query aliases defined in `reader.queries` section]
|
||||
# detection_direction: 'both' # meaning both drops and spikes will be captured
|
||||
# min_dev_from_expected: [0.0, 0.0] # meaning, no minimal threshold is applied to prevent smaller anomalies
|
||||
# scale: [1.0, 1.0] # if needed, prediction intervals' width can be increased (>1) or narrowed (<1)
|
||||
# clip_predictions: False # if data_range for respective `queries` is set in reader, `yhat.*` columns will be clipped
|
||||
# anomaly_score_outside_data_range: 1.01 # auto anomaly score (1.01) if `y` (real value) is outside of data_range, if set
|
||||
@@ -1166,13 +1156,10 @@ models:
|
||||
# See https://docs.victoriametrics.com/anomaly-detection/components/models/#common-args
|
||||
#
|
||||
# provide_series: ['anomaly_score', 'yhat', 'yhat_lower', 'yhat_upper', 'trend']
|
||||
# schedulers: [
|
||||
# all scheduler aliases defined in `scheduler` section,
|
||||
# ]
|
||||
# queries: [
|
||||
# all query aliases defined in `reader.queries` section,
|
||||
# ]
|
||||
# Configure detection_direction and minimum-deviation policies under reader.queries.<alias> (query-level from v1.30.2).
|
||||
# schedulers: [all scheduler aliases defined in `scheduler` section]
|
||||
# queries: [all query aliases defined in `reader.queries` section]
|
||||
# detection_direction: 'both' # meaning both drops and spikes will be captured
|
||||
# min_dev_from_expected: [0.0, 0.0] # meaning, no minimal threshold is applied to prevent smaller anomalies
|
||||
# scale: [1.0, 1.0] # if needed, prediction intervals' width can be increased (>1) or narrowed (<1)
|
||||
# clip_predictions: False # if data_range for respective `queries` is set in reader, `yhat.*` columns will be clipped
|
||||
# anomaly_score_outside_data_range: 1.01 # auto anomaly score (1.01) if `y` (real value) is outside of data_range, if set
|
||||
@@ -1268,12 +1255,8 @@ models:
|
||||
# See https://docs.victoriametrics.com/anomaly-detection/components/models/#common-args
|
||||
#
|
||||
# provide_series: ['anomaly_score', 'yhat', 'yhat_lower', 'yhat_upper']
|
||||
# schedulers: [
|
||||
# all scheduler aliases defined in `scheduler` section,
|
||||
# ]
|
||||
# queries: [
|
||||
# all query aliases defined in `reader.queries` section,
|
||||
# ]
|
||||
# schedulers: [all scheduler aliases defined in `scheduler` section]
|
||||
# queries: [all query aliases defined in `reader.queries` section]
|
||||
# anomaly_score_outside_data_range: 1.01 # auto anomaly score (1.01) if `y` (real value) is outside of data_range, if set
|
||||
```
|
||||
|
||||
@@ -1334,13 +1317,10 @@ models:
|
||||
# See https://docs.victoriametrics.com/anomaly-detection/components/models/#common-args
|
||||
#
|
||||
# provide_series: ['anomaly_score', 'yhat', 'yhat_lower', 'yhat_upper']
|
||||
# schedulers: [
|
||||
# all scheduler aliases defined in `scheduler` section,
|
||||
# ]
|
||||
# queries: [
|
||||
# all query aliases defined in `reader.queries` section,
|
||||
# ]
|
||||
# Configure detection_direction and minimum-deviation policies under reader.queries.<alias> (query-level from v1.30.2).
|
||||
# schedulers: [all scheduler aliases defined in `scheduler` section]
|
||||
# queries: [all query aliases defined in `reader.queries` section]
|
||||
# detection_direction: 'both' # meaning both drops and spikes will be captured
|
||||
# min_dev_from_expected: [0.0, 0.0] # meaning, no minimal threshold is applied to prevent smaller anomalies
|
||||
# scale: [1.0, 1.0] # if needed, prediction intervals' width can be increased (>1) or narrowed (<1)
|
||||
# clip_predictions: False # if data_range for respective `queries` is set in reader, `yhat.*` columns will be clipped
|
||||
# anomaly_score_outside_data_range: 1.01 # auto anomaly score (1.01) if `y` (real value) is outside of data_range, if set
|
||||
@@ -1380,13 +1360,10 @@ models:
|
||||
# See https://docs.victoriametrics.com/anomaly-detection/components/models/#common-args
|
||||
#
|
||||
# provide_series: ['anomaly_score', 'yhat', 'yhat_lower', 'yhat_upper']
|
||||
# schedulers: [
|
||||
# all scheduler aliases defined in `scheduler` section,
|
||||
# ]
|
||||
# queries: [
|
||||
# all query aliases defined in `reader.queries` section,
|
||||
# ]
|
||||
# Configure detection_direction and minimum-deviation policies under reader.queries.<alias> (query-level from v1.30.2).
|
||||
# schedulers: [all scheduler aliases defined in `scheduler` section]
|
||||
# queries: [all query aliases defined in `reader.queries` section]
|
||||
# detection_direction: 'both' # meaning both drops and spikes will be captured
|
||||
# min_dev_from_expected: [0.0, 0.0] # meaning, no minimal threshold is applied to prevent smaller anomalies
|
||||
# scale: [1.0, 1.0] # if needed, prediction intervals' width can be increased (>1) or narrowed (<1)
|
||||
# clip_predictions: False # if data_range for respective `queries` is set in reader, `yhat.*` columns will be clipped
|
||||
# anomaly_score_outside_data_range: 1.01 # auto anomaly score (1.01) if `y` (real value) is outside of data_range, if set
|
||||
@@ -1457,7 +1434,7 @@ Create `custom_model.py` with a `CustomModel` class derived from `Model`. A conc
|
||||
- `serialize`, which returns `bytes` suitable for on-disk storage;
|
||||
- `deserialize`, which restores the same model from bytes or a file path.
|
||||
|
||||
Model-specific configuration is passed through the `args` mapping. The example below learns a stationary normal interval. It emits the standard forecast columns and uses the base-class anomaly-score calculation, so query policies such as `detection_direction`, `data_range`, and minimum deviations, together with model settings such as `scale`, continue to work.
|
||||
Model-specific configuration is passed through the `args` mapping. The example below learns a stationary normal interval. It emits the standard forecast columns and uses the base-class anomaly-score calculation, so common settings such as `detection_direction`, `data_range`, `scale`, and minimum deviations continue to work.
|
||||
|
||||
```python
|
||||
from pickle import dumps
|
||||
@@ -1585,7 +1562,7 @@ See the [component configuration reference](https://docs.victoriametrics.com/ano
|
||||
Pull the `vmanomaly` image:
|
||||
|
||||
```sh
|
||||
docker pull victoriametrics/vmanomaly:v1.30.2
|
||||
docker pull victoriametrics/vmanomaly:v1.30.1
|
||||
```
|
||||
|
||||
Mount the module at `/vmanomaly/src/model/custom.py`, which matches the configured import path `model.custom.CustomModel`. Validate the complete configuration with `--dryRun` before starting the long-running service.
|
||||
@@ -1595,7 +1572,7 @@ docker run --rm \
|
||||
-v "$PWD/license:/license:ro" \
|
||||
-v "$PWD/custom_model.py:/vmanomaly/src/model/custom.py:ro" \
|
||||
-v "$PWD/config.yaml:/config.yaml:ro" \
|
||||
victoriametrics/vmanomaly:v1.30.2 \
|
||||
victoriametrics/vmanomaly:v1.30.1 \
|
||||
/config.yaml \
|
||||
--licenseFile=/license \
|
||||
--dryRun
|
||||
@@ -1691,13 +1668,10 @@ models:
|
||||
# See https://docs.victoriametrics.com/anomaly-detection/components/models/#common-args
|
||||
#
|
||||
# provide_series: ['anomaly_score', 'yhat', 'yhat_lower', 'yhat_upper']
|
||||
# schedulers: [
|
||||
# all scheduler aliases defined in `scheduler` section,
|
||||
# ]
|
||||
# queries: [
|
||||
# all query aliases defined in `reader.queries` section,
|
||||
# ]
|
||||
# Configure detection_direction and minimum-deviation policies under reader.queries.<alias> (query-level from v1.30.2).
|
||||
# schedulers: [all scheduler aliases defined in `scheduler` section]
|
||||
# queries: [all query aliases defined in `reader.queries` section]
|
||||
# detection_direction: 'both' # meaning both drops and spikes will be captured
|
||||
# min_dev_from_expected: [0.0, 0.0] # meaning, no minimal threshold is applied to prevent smaller anomalies
|
||||
# scale: [1.0, 1.0] # if needed, prediction intervals' width can be increased (>1) or narrowed (<1)
|
||||
# clip_predictions: False # if data_range for respective `queries` is set in reader, `yhat.*` columns will be clipped
|
||||
# anomaly_score_outside_data_range: 1.01 # auto anomaly score (1.01) if `y` (real value) is outside of data_range, if set
|
||||
@@ -1736,13 +1710,10 @@ models:
|
||||
# See https://docs.victoriametrics.com/anomaly-detection/components/models/#common-args
|
||||
#
|
||||
# provide_series: ['anomaly_score', 'yhat', 'yhat_lower', 'yhat_upper']
|
||||
# schedulers: [
|
||||
# all scheduler aliases defined in `scheduler` section,
|
||||
# ]
|
||||
# queries: [
|
||||
# all query aliases defined in `reader.queries` section,
|
||||
# ]
|
||||
# Configure detection_direction and minimum-deviation policies under reader.queries.<alias> (query-level from v1.30.2).
|
||||
# schedulers: [all scheduler aliases defined in `scheduler` section]
|
||||
# queries: [all query aliases defined in `reader.queries` section]
|
||||
# detection_direction: 'both' # meaning both drops and spikes will be captured
|
||||
# min_dev_from_expected: [0.0, 0.0] # meaning, no minimal threshold is applied to prevent smaller anomalies
|
||||
# scale: [1.0, 1.0] # if needed, prediction intervals' width can be increased (>1) or narrowed (<1)
|
||||
# clip_predictions: False # if data_range for respective `queries` is set in reader, `yhat.*` columns will be clipped
|
||||
# anomaly_score_outside_data_range: 1.01 # auto anomaly score (1.01) if `y` (real value) is outside of data_range, if set
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
---
|
||||
title: Monitoring
|
||||
description: "Self-monitoring via push and pull models."
|
||||
weight: 5
|
||||
menu:
|
||||
docs:
|
||||
@@ -333,14 +334,6 @@ For detailed guidance on configuring mTLS parameters such as `verify_tls`, `tls_
|
||||
<tr>
|
||||
<td>
|
||||
|
||||
<span style="white-space: nowrap;">`vmanomaly_native_threads_per_worker`</span>
|
||||
</td>
|
||||
<td>Gauge</td>
|
||||
<td>Effective maximum native numerical-library threads per model worker{{% available_from "v1.30.2" anomaly %}} after resolving [`settings.native_threads_per_worker`](https://docs.victoriametrics.com/anomaly-detection/components/settings/#parallelization) against the effective worker count and container-aware CPU capacity.</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>
|
||||
|
||||
<span style="white-space: nowrap;">`vmanomaly_config_entities`</span>
|
||||
</td>
|
||||
<td>Gauge</td>
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
---
|
||||
title: Reader
|
||||
description: "Data reader configuration. MetricsQL queries from VictoriaMetrics or LogsQL from VictoriaLogs/VictoriaTraces."
|
||||
weight: 2
|
||||
menu:
|
||||
docs:
|
||||
@@ -59,7 +60,7 @@ reader:
|
||||
step: '10s' # individual step for this query, will be filled with `sampling_period` from the root level
|
||||
data_range: ['-inf', 'inf'] # by default, no constraints applied on data range
|
||||
tz: 'UTC' # by default, tz-free data is used throughout the model lifecycle
|
||||
# from v1.30.2, explicitly add detection_direction and minimum-deviation policies here when needed
|
||||
# new query-level arguments will be added in backward-compatible way in future releases
|
||||
```
|
||||
{{% /collapse %}}
|
||||
|
||||
@@ -85,16 +86,6 @@ There is change {{% available_from "v1.13.0" anomaly %}} of [`queries`](https://
|
||||
|
||||
> If not set explicitly (or if older config style prior to [v1.13.0](https://docs.victoriametrics.com/anomaly-detection/changelog/#v1130)) is used, then it is set to reader-level `data_range` arg{{% available_from "v1.18.1" anomaly %}}
|
||||
|
||||
> Configuring `data_range` in a model is {{% deprecated_from "v1.30.2" anomaly %}}. Configure it under `reader.queries.<alias>` so the KPI domain remains the same when the query is attached to different models. Existing model-level values remain compatible as model-local fallbacks when the query does not define an explicit value.
|
||||
|
||||
- `detection_direction`{{% available_from "v1.30.2" anomaly %}} (`both`, `above_expected`, or `below_expected`): controls whether deviations on both sides, only above the expected value, or only below it can produce anomaly scores. The default is `both`. See [detection direction](https://docs.victoriametrics.com/anomaly-detection/components/models/#detection-direction) for behavior details.
|
||||
|
||||
- `min_dev_from_expected`{{% available_from "v1.30.2" anomaly %}} (float or one/two-element list[float]): ignores deviations smaller than the configured absolute threshold. A scalar or one-element list applies to both directions; a two-element list configures lower and upper deviations separately. See [minimal deviation from expected](https://docs.victoriametrics.com/anomaly-detection/components/models/#minimal-deviation-from-expected).
|
||||
|
||||
- `min_rel_dev_from_expected`{{% available_from "v1.30.2" anomaly %}} (float or one/two-element list[float]): ignores deviations smaller than the configured percentage of the absolute expected value. A scalar or one-element list applies to both directions; a two-element list configures lower and upper percentages separately. See [minimal relative deviation from expected](https://docs.victoriametrics.com/anomaly-detection/components/models/#minimal-relative-deviation-from-expected).
|
||||
|
||||
> Configuring `detection_direction`, `min_dev_from_expected`, or `min_rel_dev_from_expected` in a model is {{% deprecated_from "v1.30.2" anomaly %}}. Query-level values are authoritative. Existing model-level values remain compatible only as model-local fallbacks for attached queries that do not define the corresponding policy.
|
||||
|
||||
- `max_points_per_query`{{% available_from "v1.17.0" anomaly %}} (int): Optional arg, overrides how `search.maxPointsPerTimeseries` flag{{% available_from "v1.14.1" anomaly %}} impacts `vmanomaly` on splitting long `fit_window` [queries](https://docs.victoriametrics.com/anomaly-detection/components/reader/#vm-reader) into smaller sub-intervals. This helps users avoid hitting the `search.maxQueryDuration` limit for individual queries by distributing initial query across multiple subquery requests with minimal overhead. Set less than `search.maxPointsPerTimeseries` if hitting `maxQueryDuration` limits. If set on a query-level, it overrides the global `max_points_per_query` (reader-level).
|
||||
|
||||
- `tz`{{% available_from "v1.18.0" anomaly %}} (string): this optional argument enables timezone specification per query, overriding the reader’s default `tz`. This setting helps to account for local timezone shifts, such as [DST](https://en.wikipedia.org/wiki/Daylight_saving_time), in models that are sensitive to seasonal variations (e.g., [`TemporalEnvelopeModel`](https://docs.victoriametrics.com/anomaly-detection/components/models/#temporal-envelope) or [`OnlineQuantileModel`](https://docs.victoriametrics.com/anomaly-detection/components/models/#online-seasonal-quantile)).
|
||||
@@ -125,10 +116,7 @@ reader:
|
||||
ingestion_rate_t1:
|
||||
expr: 'sum(rate(vm_rows_inserted_total[5m])) by (type) > 0'
|
||||
step: '2m' # overrides global `sampling_period` of 1m
|
||||
data_range: [10, 'inf'] # query-level business policy from v1.30.2; y < 10 triggers anomaly score > 1
|
||||
detection_direction: 'above_expected' # query-level from v1.30.2; only spikes can be anomalous
|
||||
min_dev_from_expected: [0, 5] # query-level from v1.30.2; ignore upward deviations smaller than 5
|
||||
min_rel_dev_from_expected: [0, 15] # query-level from v1.30.2; ignore upward deviations below 15%
|
||||
data_range: [10, 'inf'] # meaning only positive values > 10 are expected, i.e. a value `y` < 10 will trigger anomaly score > 1
|
||||
max_points_per_query: 5000 # overrides reader-level value of 10000 for `ingestion_rate` query
|
||||
tz: 'America/New_York' # to override reader-wise `tz`
|
||||
tenant_id: '1:0' # overriding tenant_id to isolate data
|
||||
@@ -315,19 +303,6 @@ Optional timeout {{% available_from "v1.30.0" anomaly %}} for post-fetch process
|
||||
<tr>
|
||||
<td>
|
||||
|
||||
<span style="white-space: nowrap;">`workers`</span>
|
||||
</td>
|
||||
<td>
|
||||
|
||||
`0`
|
||||
</td>
|
||||
<td>
|
||||
Maximum concurrent datasource fetch threads {{% available_from "v1.30.2" anomaly %}}. `0` selects a bounded value automatically from the number of queries and available CPUs. A positive value sets an explicit cap for queries and disk-streamed split-query chunks.
|
||||
</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>
|
||||
|
||||
<span style="white-space: nowrap;">`verify_tls`</span>
|
||||
</td>
|
||||
<td>
|
||||
@@ -536,7 +511,6 @@ reader:
|
||||
timeout: '30s' # backward-compatible default for both phases
|
||||
fetch_timeout: '30s' # timeout for each datasource request, overrides `timeout` if set
|
||||
processing_timeout: '1m' # timeout for preparing fetched series for fit/infer, overrides `timeout` if set
|
||||
workers: 0 # automatic bounded datasource concurrency; set a positive value for an explicit cap
|
||||
query_from_last_seen_timestamp: True # false by default
|
||||
latency_offset: '1ms'
|
||||
series_processing_batch_size: 8
|
||||
@@ -923,19 +897,6 @@ Optional timeout {{% available_from "v1.30.0" anomaly %}} for post-fetch process
|
||||
<tr>
|
||||
<td>
|
||||
|
||||
<span style="white-space: nowrap;">`workers`</span>
|
||||
</td>
|
||||
<td>
|
||||
|
||||
`0`
|
||||
</td>
|
||||
<td>
|
||||
Maximum concurrent datasource fetch threads {{% available_from "v1.30.2" anomaly %}}. `0` selects a bounded value automatically from the number of queries and available CPUs. A positive value sets an explicit cap for queries and disk-streamed split-query chunks.
|
||||
</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>
|
||||
|
||||
<span style="white-space: nowrap;">`verify_tls`</span>
|
||||
</td>
|
||||
<td>
|
||||
@@ -1077,15 +1038,12 @@ reader:
|
||||
timeout: '30s' # backward-compatible default for both phases
|
||||
fetch_timeout: '30s' # timeout for each datasource request, overrides `timeout` if set
|
||||
processing_timeout: '1m' # timeout for preparing fetched series for fit/infer, overrides `timeout` if set
|
||||
workers: 0 # automatic bounded datasource concurrency; set a positive value for an explicit cap
|
||||
queries:
|
||||
# one query returning 1 result fields (avg_duration), it will have __name__ label (series name) as `duration_30m__avg`
|
||||
duration_avg_30m:
|
||||
expr: "* | stats avg(duration) as avg" # initial LogsQL expression
|
||||
step: '2m' # overrides global `sampling_period` of 1m
|
||||
data_range: [0, 'inf'] # query-level business policy from v1.30.2; y < 0 triggers anomaly score > 1
|
||||
detection_direction: 'above_expected' # query-level from v1.30.2
|
||||
min_rel_dev_from_expected: [0, 20] # query-level from v1.30.2; ignore upward deviations below 20%
|
||||
data_range: [0, 'inf'] # meaning only positive values > 0 are expected, i.e. a value `y` < 0 will trigger anomaly score > 1
|
||||
tz: 'America/New_York' # to override reader-wise `tz`
|
||||
# tenant_id: '1:0' # overriding tenant_id to isolate data
|
||||
# offset: '-15s' # to override reader-wise `offset` and query data 15 seconds earlier to account for data collection delays
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
---
|
||||
title: Scheduler
|
||||
description: "Scheduling configuration. Inference frequency and training time range."
|
||||
weight: 3
|
||||
menu:
|
||||
docs:
|
||||
@@ -70,7 +71,6 @@ options={`"scheduler.periodic.PeriodicScheduler"`, `"scheduler.oneoff.OneoffSche
|
||||
|
||||
## Periodic scheduler
|
||||
|
||||
> [!WARNING]
|
||||
> If `start_from` [parameter](#parameters-1) is used, it's suggested to also set `restore_state: true` in the [Settings section](https://docs.victoriametrics.com/anomaly-detection/components/settings/#state-restoration) of a config, so that the scheduler can restore its state from the previous run **if terminated or restarted in between scheduled runs** and continue producing anomaly scores without interruptions, otherwise the service will be idle until future `start_from` time is reached. E.g. if `start_from` is set to `20:00` and the service is started and then terminated and restarted at `20:30`, it will not produce any anomaly scores until the next day's `20:00` is reached (+23:30 of being idle), which introduces inconvenience for the users.
|
||||
|
||||
> {{% available_from "v1.30.0" anomaly %}} If a periodic scheduler worker exits unexpectedly, the service attempts bounded restarts with exponential backoff instead of shutting down unrelated schedulers. Monitor [`vmanomaly_scheduler_alive`](https://docs.victoriametrics.com/anomaly-detection/components/monitoring/#startup-metrics) and `vmanomaly_scheduler_restarts_total` to alert on persistent failures.
|
||||
@@ -197,7 +197,6 @@ This configuration specifies that `vmanomaly` will calculate a 14-day time windo
|
||||
|
||||
## Oneoff scheduler
|
||||
|
||||
> [!WARNING]
|
||||
> As of latest version, the Oneoff scheduler can't be explicitly used with a combination of [stateful service](https://docs.victoriametrics.com/anomaly-detection/components/settings/#state-restoration). It is designed to run once and exit, so it does not maintain state across runs. A warning will be raised in logs and internal state for such scheduler will not be saved and restored upon restart. If you need to run the scheduler periodically and/or maintain state, consider using the [Periodic scheduler](#periodic-scheduler) instead.
|
||||
|
||||
### Parameters
|
||||
@@ -369,7 +368,6 @@ schedulers:
|
||||
|
||||
> {{% available_from "v1.26.0" anomaly %}} `BacktestingScheduler` in [inference-only](https://docs.victoriametrics.com/anomaly-detection/components/scheduler/#inference-only-mode) mode is used in UI for backtesting configurations on historical data to verify that it works as expected before it goes live. See [vmanomaly UI](https://docs.victoriametrics.com/anomaly-detection/ui/) on how to access and use the UI.
|
||||
|
||||
> [!WARNING]
|
||||
> As of latest version, the Backtesting scheduler can't be explicitly used with a combination of [state restoration](https://docs.victoriametrics.com/anomaly-detection/components/settings/#state-restoration). It is designed to run once and exit, so it does not maintain state across runs. A warning will be raised in logs and internal state for such scheduler will not be saved and restored upon restart. If you need to run the scheduler periodically and/or maintain state, consider using the [Periodic scheduler](#periodic-scheduler) instead.
|
||||
|
||||
> A new, more intuitive backtesting mode is available {{% available_from "v1.22.1" anomaly %}}. In **Inference only** mode, the window you specify via `[from, to]` (or `[from_iso, to_iso]`) is used *solely for inference*, and the corresponding training (“fit”) windows are determined automatically. To enable this behavior, set:
|
||||
|
||||
|
Before Width: | Height: | Size: 127 KiB |
|
After Width: | Height: | Size: 32 KiB |
|
After Width: | Height: | Size: 29 KiB |
|
After Width: | Height: | Size: 32 KiB |
|
Before Width: | Height: | Size: 73 KiB |
|
After Width: | Height: | Size: 30 KiB |
|
After Width: | Height: | Size: 30 KiB |
|
After Width: | Height: | Size: 32 KiB |
|
Before Width: | Height: | Size: 63 KiB |
|
Before Width: | Height: | Size: 63 KiB |
@@ -1,5 +1,6 @@
|
||||
---
|
||||
title: Server
|
||||
description: "HTTP server. REST API, /metrics endpoint, and web UI."
|
||||
weight: 7
|
||||
menu:
|
||||
docs:
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
---
|
||||
title: Settings
|
||||
description: "Global settings for the anomaly detection service."
|
||||
weight: 6
|
||||
menu:
|
||||
docs:
|
||||
@@ -16,7 +17,7 @@ aliases:
|
||||
Through the **Settings** section of a config, you can configure the following parameters of the anomaly detection service:
|
||||
|
||||
- [Anomaly score outside data range](#anomaly-score-outside-data-range) - specific anomaly score fo values outside the expected data range of particular query
|
||||
- [Parallelization](#parallelization) - process workers and native numerical-library threads used by each worker
|
||||
- [Parallelization](#parallelization) - number of workers to run workloads in parallel
|
||||
- [State restoration](#state-restoration) - whether to restore models' state in between runs if the service is restarted or stopped
|
||||
|
||||
## Anomaly Score Outside Data Range
|
||||
@@ -36,7 +37,7 @@ settings:
|
||||
schedulers:
|
||||
periodic:
|
||||
class: periodic
|
||||
fit_every: 1000d # bootstrap-only schedule; use a finite cadence if accumulated state must be reset
|
||||
fit_every: 5m
|
||||
fit_window: 3h
|
||||
infer_every: 30s
|
||||
# other schedulers
|
||||
@@ -45,14 +46,12 @@ models:
|
||||
zscore_online_inherited:
|
||||
class: zscore_online
|
||||
z_threshold: 3.5
|
||||
decay: 0.99 # give more weight to recent data while using the bootstrap-only fit schedule
|
||||
clip_predictions: True
|
||||
# will be inherited from settings.anomaly_score_outside_data_range
|
||||
# anomaly_score_outside_data_range: 5.0
|
||||
zscore_online_override:
|
||||
class: zscore_online
|
||||
z_threshold: 3.5
|
||||
decay: 0.99 # give more weight to recent data while using the bootstrap-only fit schedule
|
||||
clip_predictions: True
|
||||
anomaly_score_outside_data_range: 1.5 # will override settings.anomaly_score_outside_data_range
|
||||
# other models
|
||||
@@ -88,29 +87,24 @@ monitoring:
|
||||
# other monitoring settings
|
||||
```
|
||||
|
||||
The examples on this page use `fit_every: 1000d` as an effectively bootstrap-only schedule. This is appropriate when an online model has a suitable forgetting or reactivity mechanism, such as `zscore_online` with `decay < 1`. If outdated history must be discarded explicitly, choose a finite fit cadence instead; each fit resets the online model state from the configured `fit_window`.
|
||||
|
||||
## Parallelization
|
||||
|
||||
The `n_workers` argument allows you to explicitly specify the number of process workers for internal parallelization of the service. This can help improve performance on multicore systems by allowing the service to process multiple tasks in parallel. For backward compatibility, it is set to `1` by default. It should be an integer greater than or equal to `-1`; values `-1` and `0` use the number of CPU cores available to the service, including container CPU limits.
|
||||
The `n_workers` argument allows you to explicitly specify the number of workers for internal parallelization of the service. This can help improve performance on multicore systems by allowing the service to process multiple tasks in parallel. For backward compatibility, it's set to `1` by default, meaning that the service will run in a single-threaded mode. It should be an integer greater than or equal to `-1`, where `-1` and `0` means that the service will automatically inherit the number of workers based on the number of available CPU cores.
|
||||
|
||||
The `native_threads_per_worker` argument {{% available_from "v1.30.2" anomaly %}} limits [native numerical-library threads](https://scikit-learn.org/stable/computing/parallelism.html#oversubscription-spawning-too-many-threads), such as OpenBLAS threads, inside each model worker. Its default `0` divides the CPU capacity available to the service across effective workers automatically. A positive integer requests an explicit per-worker limit, capped by the CPU share available to that worker. This avoids oversubscription and CPU throttling when every process would otherwise start its own multi-threaded numerical workload. Both `n_workers` and `native_threads_per_worker` are startup settings and require a service restart to change.
|
||||
|
||||
- **Increasing** the number can be particularly useful when dealing with a high volume of queries returning many (long) timeseries.
|
||||
- **Decreasing** the number can be useful when running the service on a system with limited resources or when you want to reduce the load on the system.
|
||||
Increasing the number can be particularly useful when dealing with a high volume of queries returning many (long) timeseries.
|
||||
Decreasing the number can be useful when running the service on a system with limited resources or when you want to reduce the load on the system.
|
||||
|
||||
Here's an example configuration that uses 4 workers for service's internal parallelization:
|
||||
|
||||
```yaml
|
||||
settings:
|
||||
n_workers: 4
|
||||
native_threads_per_worker: 0 # automatically divide available CPU capacity across workers
|
||||
restore_state: False # do not restore state from previous run
|
||||
|
||||
schedulers:
|
||||
periodic:
|
||||
class: periodic
|
||||
fit_every: 1000d # bootstrap-only schedule; use a finite cadence if accumulated state must be reset
|
||||
fit_every: 5m
|
||||
fit_window: 3h
|
||||
infer_every: 30s
|
||||
# other schedulers
|
||||
@@ -119,7 +113,6 @@ models:
|
||||
zscore_online_override:
|
||||
class: zscore_online
|
||||
z_threshold: 3.5
|
||||
decay: 0.99 # give more weight to recent data while using the bootstrap-only fit schedule
|
||||
clip_predictions: True
|
||||
# other models
|
||||
|
||||
@@ -157,11 +150,10 @@ monitoring:
|
||||
|
||||
> This feature is best used with config [hot-reloading](https://docs.victoriametrics.com/anomaly-detection/components/#hot-reload) {{% available_from "v1.25.0" anomaly %}} for increased deployment flexibility.
|
||||
|
||||
The `restore_state` argument {{% available_from "v1.24.0" anomaly %}} makes `vmanomaly` service **stateful** by persisting and restoring service metadata and fitted model state between runs, allowing seamless continuation after service restarts.
|
||||
The `restore_state` argument {{% available_from "v1.24.0" anomaly %}} makes `vmanomaly` service **stateful** by persisting and restoring state between runs. If enabled, the service will save the state of anomaly detection models and their training data to local filesystem, allowing for seamless continuation of operations after service restarts.
|
||||
|
||||
By default, `restore_state` is set to `false`, meaning the service will start fresh on each restart, to maintain backward compatibility.
|
||||
|
||||
> [!WARNING]
|
||||
> This feature requires enabling [on-disk mode](https://docs.victoriametrics.com/anomaly-detection/faq/#on-disk-mode) for the models and data. If not enabled, the service will exit with an error when `restore_state` is set to `true`.
|
||||
|
||||
### Benefits
|
||||
@@ -173,17 +165,15 @@ This feature improves the experience of using the anomaly detection service in s
|
||||
|
||||
### How it works
|
||||
|
||||
**Storage**: The service dumps its state into a database file located at `$VMANOMALY_MODEL_DUMPS_DIR/vmanomaly.db`. This database contains metadata about model configurations and schedulers, together with references to trained model artifacts. Scheduler-managed Parquet data is temporary fit input rather than durable model state.
|
||||
**Storage**: The service dumps its state into a database file located at `$VMANOMALY_MODEL_DUMPS_DIR/vmanomaly.db`. This database contains metadata about model configurations, schedulers and references to the trained model instances and their respective data.
|
||||
|
||||
**State restoration**: When the service starts with `restore_state` set to `true`, it will:
|
||||
1. Check for the existence of the database file in the specified directory.
|
||||
2. If the file does not exist, it will create a new database file and initialize the state with the current configuration, training models as needed. If the file exists, then it compares the loaded state with the current configuration to determine what can be reused and what needs to be retrained (for example, a changed model class, hyperparameter, scheduler, or reader query invalidates the affected state). Compatible model configurations and trained model instances are restored.
|
||||
3. Subsequently, it checks model "staleness" and retrains models if necessary, based on the current configuration and the last training time stored in the database versus the next scheduled training time. If the model is **actual**, it continues to use the previously trained model instance. If the model is **stale** (for example, `fit_every` has passed since the last training), it reads the latest `fit_window` from VictoriaMetrics and retrains the model.
|
||||
2. If the file does not exist, it will create a new database file and initialize the state with the current configuration, training models as needed. If the file exists, then it compares the loaded state with the current configuration to ensure compatibility - what can be reused and what needs to be retrained (e.g., if the model class or hyperparameters have changed, it will not restore the state for that model, same for schedulers or reader queries). For reusable components, previously saved state, including model configurations, trained model instances, and their training data, will be restored.
|
||||
3. Subsequently, it will check for model "staleness" and retrain models if necessary, based on the current configuration and the last training time stored in the database vs next scheduled training time. If the model is **actual**, it will continue to use the previously trained model instances or its training data. If the model is **stale** (e.g. `fit_every` time has passed since the last training), it will retrain the model using the latest data of `fit_window` length from VictoriaMetrics TSDB.
|
||||
|
||||
**State update**: The service periodically saves the updated state after each "atomic" operations, such as (model_alias, query_alias)-based training or inference. This ensures that the state is always up-to-date and can be restored in case of a service restart. [Online models](https://docs.victoriametrics.com/anomaly-detection/components/models/#online-models) are also updated after each inference, while [offline models](https://docs.victoriametrics.com/anomaly-detection/components/models/#offline-models) are only saved after each training operation as they do not change the state during consecutive fit calls.
|
||||
|
||||
**Fit-data cleanup**: {{% available_from "v1.30.2" anomaly %}} Each scheduler-managed Parquet generation is removed after all dependent univariate or multivariate models finish fitting and commit their state. Failed or overlapping fits retain their own generation until it is safe to clean up. This keeps the initial bootstrap window available while it is in use without retaining it for the full `fit_every` interval.
|
||||
|
||||
**Cleanup behavior**: When `restore_state` is switched from `true` to `false`, the database file is automatically removed on the next service startup to prevent inconsistent behavior. All the artifacts (such as model dumps and data dumps) will be removed as well, so the service will start fresh without any previous state.
|
||||
|
||||
Here's an example configuration that enables state restoration:
|
||||
@@ -196,7 +186,7 @@ settings:
|
||||
schedulers:
|
||||
periodic:
|
||||
class: periodic
|
||||
fit_every: 1000d # bootstrap-only schedule; use a finite cadence if accumulated state must be reset
|
||||
fit_every: 5m
|
||||
fit_window: 3h
|
||||
infer_every: 30s
|
||||
# other schedulers
|
||||
@@ -205,7 +195,6 @@ models:
|
||||
zscore_online:
|
||||
class: zscore_online
|
||||
z_threshold: 3.5
|
||||
decay: 0.99 # give more weight to recent data while using the bootstrap-only fit schedule
|
||||
clip_predictions: True
|
||||
# other models
|
||||
|
||||
@@ -254,19 +243,16 @@ settings:
|
||||
schedulers:
|
||||
periodic_1d:
|
||||
class: periodic
|
||||
fit_every: 1000d # bootstrap-only schedule; use a finite cadence if accumulated state must be reset
|
||||
fit_every: 1h
|
||||
infer_every: 30s
|
||||
fit_window: 24h
|
||||
models:
|
||||
zscore_online:
|
||||
class: zscore_online
|
||||
z_threshold: 3.5
|
||||
decay: 0.99 # give more weight to recent data while using the bootstrap-only fit schedule
|
||||
schedulers: ['periodic_1d']
|
||||
temporal_envelope:
|
||||
class: temporal_envelope
|
||||
alpha: 0.005 # adapt the trend while using the bootstrap-only fit schedule
|
||||
loss_reactivity: 5 # allow new deviations to update the envelope
|
||||
schedulers: ['periodic_1d']
|
||||
queries: ['q1', 'q2']
|
||||
seasonalities: ['hod_smooth', 'dow_smooth']
|
||||
@@ -283,7 +269,7 @@ reader:
|
||||
# other components like writer, monitoring, etc.
|
||||
```
|
||||
|
||||
if the service is restarted before the next scheduled fit, it will restore the state of the `zscore_online` and `temporal_envelope` models if their signature (class, hyperparameters, schedulers, etc.) has not changed. It loads trained model instances from disk and continues producing [anomaly scores](https://docs.victoriametrics.com/anomaly-detection/faq/#what-is-anomaly-score) without retraining. If there are changes or new queries added to the configuration, the service will add these to scheduled jobs for fit and infer. That's what is changed and what is restored in a config below:
|
||||
if the service is restarted in less than 1 hour after the last training (now < next scheduled fit time), it will restore the state of the `zscore_online` and `temporal_envelope` models if their signature (class, hyperparameters, schedulers, etc.) has not changed. It will load the trained model instances or their training data from disk and continue producing [anomaly scores](https://docs.victoriametrics.com/anomaly-detection/faq/#what-is-anomaly-score) without retraining. If there are changes or new queries added to the configuration, the service will add these to scheduled jobs for fit and infer. That's what is changed and what is restored in a config below:
|
||||
|
||||
```yaml
|
||||
settings:
|
||||
@@ -292,19 +278,16 @@ settings:
|
||||
schedulers:
|
||||
periodic_1d: # can be fully reused, no changes
|
||||
class: periodic
|
||||
fit_every: 1000d # unchanged bootstrap-only schedule
|
||||
fit_every: 1h # unchanged, still fits every hour
|
||||
infer_every: 30s # unchanged, still infers every 30 seconds
|
||||
fit_window: 24h # unchanged, still fits on the last 24 hours of data
|
||||
models:
|
||||
zscore_online: # can't be reused, because its `z_threshold` has changed
|
||||
class: zscore_online # unchanged, still the same model class
|
||||
z_threshold: 3.0 # changed, needs retraining!
|
||||
decay: 0.99 # unchanged forgetting factor
|
||||
schedulers: ['periodic_1d'] # unchanged, still attached to the same scheduler
|
||||
temporal_envelope: # can be partially reused, because its class and schedulers are unchanged but queries have changed
|
||||
class: temporal_envelope # unchanged, still the same model class
|
||||
alpha: 0.005 # unchanged trend reactivity
|
||||
loss_reactivity: 5 # unchanged envelope reactivity
|
||||
schedulers: ['periodic_1d'] # unchanged, still attached to the same scheduler
|
||||
queries: ['q1', 'q3'] # changed, added new query 'q3', drops 'q2', so (temporal_envelope, q2) should be trained from scratch
|
||||
seasonalities: ['hod_smooth', 'dow_smooth'] # unchanged
|
||||
@@ -332,31 +315,31 @@ This means that the service upon restart:
|
||||
|
||||
## Retention
|
||||
|
||||
{{% available_from "v1.28.1" anomaly %}} The `retention` argument sets a [time to live](https://en.wikipedia.org/wiki/Time_to_live) (TTL) for stored model instances. At each `check_interval`, the service removes instances that have not been used for inference or refitting within `ttl`. This bounds stale resource usage in long-running deployments. Temporary scheduler-managed fit data follows the [fit-data cleanup lifecycle](#how-it-works) independently.
|
||||
{{% available_from "v1.28.1" anomaly %}} The `retention` argument sets a [time to live](https://en.wikipedia.org/wiki/Time_to_live) (TTL) for service artifacts such as stored model instances and training data. At each `check_interval`, the service removes artifacts that have not been used for inference or refitting within `ttl`. This bounds stale resource usage in long-running deployments.
|
||||
|
||||
### Use Cases
|
||||
- With **[online models](https://docs.victoriametrics.com/anomaly-detection/components/models/#online-models)** as they continuously create model instances for new timeseries over time during inference calls, especially when combined with [periodic schedulers](https://docs.victoriametrics.com/anomaly-detection/components/scheduler/#periodic-scheduler) with infrequent `fit_every` (say, `90d`).
|
||||
- In deployments where **the set of monitored timeseries changes frequently**, leading to accumulation of unused model instances due to high churn rate or relabeling of metrics.
|
||||
- When using **[state restoration](https://docs.victoriametrics.com/anomaly-detection/components/settings/#state-restoration)**, which improves fault tolerance but can retain inactive model instances unless retention is configured.
|
||||
- In deployments where **the set of monitored timeseries changes frequently**, leading to accumulation of unused model instances and training data over time, due to high churn rate or relabeling of metrics.
|
||||
- When using **[state restoration](https://docs.victoriametrics.com/anomaly-detection/components/settings/#state-restoration) feature** which improves fault tolerance, but may retain all model instances and their training data for considerable time, potentially leading to high disk or RAM usage.
|
||||
|
||||
### Configuration
|
||||
|
||||
The section is **backward-compatible and disabled by default**, meaning that model instances are retained unless:
|
||||
The section is **backward-compatible and disabled by default**, meaning that all model instances and their training data are retained unless:
|
||||
- The service is restarted with `restore_state` set to `false`, which triggers a cleanup of all stored artifacts.
|
||||
- The models are marked as outdated once scheduled re-fitting is due, leading to retraining and replacement of previous artifacts.
|
||||
|
||||
`ttl` defines the time-to-live period for model instances. It should be a valid period string (e.g., `7d` for 7 days or `30d` for 30 days). If a model instance has not been used for inference or refitting within this period, it is considered stale and eligible for cleanup.
|
||||
`ttl` argument defines the time-to-live period for model instances and their training data. It should be a valid period string (e.g., `7d` for 7 days, `30d` for 30 days, etc.). If a model instance or its training data has not been used for inference or refitting within this period, it will be considered stale and eligible for cleanup.
|
||||
|
||||
> If `ttl` is greater than a scheduler's `fit_every`, the model is refitted before it becomes stale and the TTL has no effect.
|
||||
|
||||
`check_interval` defines how often the service should check for stale artifacts. It should be a valid period string (e.g., `1h` for 1 hour or `24h` for 24 hours). During each check, the service evaluates stored model instances against the defined `ttl` and removes those that are stale.
|
||||
`check_interval` argument defines how often the service should check for stale artifacts. It should be a valid period string (e.g., `1h` for 1 hour, `24h` for 24 hours, etc.). During each check, the service will evaluate all stored model instances and their training data against the defined `ttl` and remove those that are stale.
|
||||
|
||||
> Check interval should be set to a value smaller than `ttl` and smaller than the smallest `fit_every` period among all schedulers used in the config to ensure timely cleanup of stale artifacts, otherwise stale artifacts may persist longer than intended.
|
||||
|
||||
### Example
|
||||
|
||||
Here's an example configuration that enables retention with a TTL of 1 day and a check interval of 30 minutes, where inference is performed every 15 minutes.
|
||||
- Model instances that have not been used for inference or refitting within the last day will be cleaned up every 30 minutes (m2 example on a diagram)
|
||||
- Model instances and their training data that have not been used for inference or refitting within the last day will be cleaned up every 30 minutes (m2 example on a diagram)
|
||||
- While model instances used for inference within the last day at least 1 time will be retained (m1 example on a diagram)
|
||||
|
||||

|
||||
@@ -400,7 +383,7 @@ settings:
|
||||
# other settings
|
||||
restore_state: True # enables state restoration
|
||||
retention:
|
||||
ttl: 24h # time-to-live for inactive model instances
|
||||
ttl: 24h # time-to-live for model instances and their training data
|
||||
check_interval: 30m # interval to check for stale artifacts
|
||||
```
|
||||
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
---
|
||||
title: Writer
|
||||
description: "Data writer. Write anomaly scores back to VictoriaMetrics."
|
||||
weight: 4
|
||||
menu:
|
||||
docs:
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
---
|
||||
title: Guides
|
||||
description: "Step-by-step guides for deploying, configuring, integrating, and operating vmanomaly for anomaly detection."
|
||||
weight: 3
|
||||
menu:
|
||||
docs:
|
||||
|
||||
@@ -124,12 +124,12 @@ Detailed parameters in each section:
|
||||
|
||||
* `schedulers` ([PeriodicScheduler](https://docs.victoriametrics.com/anomaly-detection/components/scheduler/#periodic-scheduler) is used here)
|
||||
* `infer_every` - Specifies the frequency at which the trained models perform inferences on new data, essentially determining how often new anomaly score data points are generated. Format examples: 30s, 4m, 2h, 1d (time units: 's' for seconds, 'm' for minutes, 'h' for hours, 'd' for days). This parameter essentially asks, at regular intervals (e.g., every 1 minute), whether the latest data points appear abnormal based on historical data.
|
||||
* `fit_every` - Sets the frequency for retraining the models. [Online models](https://docs.victoriametrics.com/anomaly-detection/components/models/#online-models) learn from every inference batch, so set a large value such as `1000d` to make fitting effectively bootstrap-only. For evolving behavior, configure the model's forgetting or reactivity mechanism, or choose a finite fit cadence to reset accumulated state. Format is similar to `infer_every`.
|
||||
* `fit_every` - Sets the frequency for retraining the models. A higher frequency ensures more updated models but requires more CPU resources. If omitted, models are retrained in each `infer_every` cycle. Format is similar to `infer_every`.
|
||||
* `fit_window` - Defines the data interval for training the models. Longer intervals allow for capturing extensive historical behavior and better seasonal pattern detection but may slow down the model's response to permanent metric changes and increase resource consumption. A minimum of two full seasonal cycles is recommended. Example format: 3h for three hours of data.
|
||||
|
||||
* `models`
|
||||
* `class` - Specifies the model to be used. Options include custom models ([guide here](https://docs.victoriametrics.com/anomaly-detection/components/models/#custom-model-guide)) or a selection from [built-in models](https://docs.victoriametrics.com/anomaly-detection/components/models/#built-in-models). For operational metrics with calendar behavior, use the online [Temporal Envelope](https://docs.victoriametrics.com/anomaly-detection/components/models/#temporal-envelope).
|
||||
* Model-specific parameters are configured directly below the model alias, as shown in the example.
|
||||
* `class` - Specifies the model to be used. Options include custom models ([guide here](https://docs.victoriametrics.com/anomaly-detection/components/models/#custom-model-guide)) or a selection from [built-in models](https://docs.victoriametrics.com/anomaly-detection/components/models/#built-in-models), such as the [Facebook Prophet](https://docs.victoriametrics.com/anomaly-detection/components/models/#prophet) (`model.prophet.ProphetModel`).
|
||||
* `args` - Model-specific parameters, formatted as a YAML dictionary in the `key: value` structure. Parameters available in [FB Prophet](https://facebook.github.io/prophet/docs/quick_start) can be used as an example.
|
||||
|
||||
* `reader`
|
||||
* `datasource_url` - The URL for the data source, typically an HTTP endpoint serving `/api/v1/query_range`.
|
||||
@@ -145,16 +145,16 @@ Below is an illustrative example of a `vmanomaly_config.yml` configuration file.
|
||||
schedulers:
|
||||
periodic:
|
||||
infer_every: "1m"
|
||||
fit_every: "1000d" # bootstrap-only schedule; use a finite cadence if accumulated state must be reset
|
||||
fit_window: "14d" # two weekly cycles for initial bootstrap
|
||||
fit_every: "1h"
|
||||
fit_window: "2d" # 2d-14d based on the presence of weekly seasonality in your data
|
||||
|
||||
models:
|
||||
temporal_envelope:
|
||||
class: "temporal_envelope"
|
||||
alpha: 0.005 # adapt the trend while using the bootstrap-only fit schedule
|
||||
loss_reactivity: 5 # allow new deviations to update the envelope
|
||||
seasonalities: ["hod_smooth", "dow_smooth"]
|
||||
provide_series: ["anomaly_score", "y", "yhat", "yhat_lower", "yhat_upper"]
|
||||
prophet:
|
||||
class: "prophet"
|
||||
args:
|
||||
interval_width: 0.98
|
||||
weekly_seasonality: False # comment it if your data has weekly seasonality
|
||||
yearly_seasonality: False
|
||||
|
||||
reader:
|
||||
datasource_url: "http://victoriametrics:8428/"
|
||||
@@ -279,24 +279,19 @@ global:
|
||||
scrape_configs:
|
||||
- job_name: 'vmagent'
|
||||
static_configs:
|
||||
- targets:
|
||||
- 'vmagent:8429'
|
||||
- targets: ['vmagent:8429']
|
||||
- job_name: 'vmalert'
|
||||
static_configs:
|
||||
- targets:
|
||||
- 'vmalert:8880'
|
||||
- targets: ['vmalert:8880']
|
||||
- job_name: 'victoriametrics'
|
||||
static_configs:
|
||||
- targets:
|
||||
- 'victoriametrics:8428'
|
||||
- targets: ['victoriametrics:8428']
|
||||
- job_name: 'node-exporter'
|
||||
static_configs:
|
||||
- targets:
|
||||
- 'node-exporter:9100'
|
||||
- targets: ['node-exporter:9100']
|
||||
- job_name: 'vmanomaly'
|
||||
static_configs:
|
||||
- targets:
|
||||
- 'vmanomaly:8490'
|
||||
- targets: [ 'vmanomaly:8490' ]
|
||||
```
|
||||
|
||||
|
||||
@@ -392,7 +387,7 @@ services:
|
||||
- "--notifier.url=http://alertmanager:9093/"
|
||||
- "--rule=/etc/alerts/*.yml"
|
||||
# display source of alerts in grafana
|
||||
- "--external.url=http://127.0.0.1:3000" # grafana outside container
|
||||
- "--external.url=http://127.0.0.1:3000" #grafana outside container
|
||||
# when copypaste the line be aware of '$$' for escaping in '$expr'
|
||||
- '--external.alert.source=explore?orgId=1&left=["now-1h","now","VictoriaMetrics",{"expr": },{"mode":"Metrics"},{"ui":[true,true,true,"none"]}]'
|
||||
networks:
|
||||
@@ -400,7 +395,7 @@ services:
|
||||
restart: always
|
||||
vmanomaly:
|
||||
container_name: vmanomaly
|
||||
image: victoriametrics/vmanomaly:v1.30.2
|
||||
image: victoriametrics/vmanomaly:v1.30.1
|
||||
depends_on:
|
||||
- "victoriametrics"
|
||||
ports:
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
---
|
||||
weight: 1
|
||||
title: Anomaly Detection and Alerting Setup
|
||||
description: "Tutorial integrating vmanomaly with vmalert, Alertmanager, and Grafana."
|
||||
menu:
|
||||
docs:
|
||||
parent: "anomaly-detection-guides"
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
---
|
||||
weight: 0
|
||||
title: Guides
|
||||
description: "Practical guides for deploying and operating VictoriaMetrics."
|
||||
disableToc: true
|
||||
|
||||
menu:
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
---
|
||||
weight: 12
|
||||
title: Collecting OpenShift logs with Victoria Logs
|
||||
description: "Collect and store OpenShift cluster logs in VictoriaLogs."
|
||||
menu:
|
||||
docs:
|
||||
parent: "guides"
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
---
|
||||
weight: 5
|
||||
title: Connecting VictoriaMetrics components to cloud storage
|
||||
description: "Configure VictoriaMetrics components to use object storage for data, backups, and other storage workflows."
|
||||
menu:
|
||||
docs:
|
||||
parent: guides
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
---
|
||||
weight: 5
|
||||
title: How to use OpenTelemetry with VictoriaMetrics and VictoriaLogs
|
||||
description: "Use OpenTelemetry with VictoriaMetrics and VictoriaLogs on Kubernetes."
|
||||
menu:
|
||||
docs:
|
||||
parent: "guides"
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
---
|
||||
weight: 4
|
||||
title: Getting started with VM Operator
|
||||
description: "Deploy the VictoriaMetrics stack on Kubernetes with the Kubernetes Operator."
|
||||
menu:
|
||||
docs:
|
||||
parent: "guides"
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
---
|
||||
weight: 5
|
||||
title: Setup vmauth - Multi-Tenant Access with Grafana & OIDC
|
||||
description: "Multi-tenant access for metrics, logs, and traces with Grafana and OIDC."
|
||||
menu:
|
||||
docs:
|
||||
parent: guides
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
---
|
||||
weight: 16
|
||||
title: Setup vmgateway - Multi-Tenant Access with Grafana & OIDC
|
||||
description: "Configure vmgateway with Grafana and OpenID Connect for authenticated, multi-tenant access to VictoriaMetrics data."
|
||||
menu: false
|
||||
tags:
|
||||
- metrics
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
---
|
||||
weight: 7
|
||||
title: How to delete or replace metrics in VictoriaMetrics
|
||||
description: "Guide to deleting or replacing time series data."
|
||||
menu:
|
||||
docs:
|
||||
parent: "guides"
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
---
|
||||
weight: 10
|
||||
title: Multi Retention Setup within VictoriaMetrics Cluster
|
||||
description: "Configure multiple retention periods in VM Cluster."
|
||||
menu:
|
||||
docs:
|
||||
parent: "guides"
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
---
|
||||
weight: 9
|
||||
title: HA monitoring setup in Kubernetes via VictoriaMetrics Cluster
|
||||
description: "High-availability Kubernetes monitoring with replication."
|
||||
menu:
|
||||
docs:
|
||||
parent: "guides"
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
---
|
||||
weight: 3
|
||||
title: Kubernetes monitoring with VictoriaMetrics Cluster
|
||||
description: "Monitor Kubernetes with VM Cluster."
|
||||
menu:
|
||||
docs:
|
||||
parent: "guides"
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
---
|
||||
weight: 2
|
||||
title: Kubernetes monitoring via VictoriaMetrics Single
|
||||
description: "Monitor Kubernetes with single-node VictoriaMetrics and Helm."
|
||||
menu:
|
||||
docs:
|
||||
parent: "guides"
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
---
|
||||
weight: 13
|
||||
title: Headlamp Kubernetes UI and VictoriaMetrics
|
||||
description: "Point Headlamp's Prometheus integration at VictoriaMetrics."
|
||||
menu:
|
||||
docs:
|
||||
parent: "guides"
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
---
|
||||
title: Migrate from InfluxDB to VictoriaMetrics
|
||||
description: "Differences and approaches for migrating from InfluxDB."
|
||||
weight: 8
|
||||
menu:
|
||||
docs:
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
---
|
||||
weight: 11
|
||||
title: 'VictoriaMetrics Multi-Regional Setup: Dedicated Monitoring'
|
||||
description: "Collect metrics across regions with dedicated monitoring."
|
||||
menu:
|
||||
docs:
|
||||
parent: guides
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
---
|
||||
weight: 9
|
||||
title: Understand Your Setup Size
|
||||
description: "Capacity planning. Active time series, ingestion rate, churn rate, QPS."
|
||||
menu:
|
||||
docs:
|
||||
parent: "guides"
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
---
|
||||
weight: 14
|
||||
title: VictoriaMetrics topologies
|
||||
description: "Choose the right deployment topology for risk tolerance and performance needs."
|
||||
menu:
|
||||
docs:
|
||||
parent: "guides"
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
---
|
||||
weight: 5
|
||||
title: Setup vmagent - Multi-Tenant remote write & OIDC
|
||||
description: "Multi-tenant remote write with OIDC and JWT tokens."
|
||||
menu:
|
||||
docs:
|
||||
parent: guides
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
---
|
||||
weight: 16
|
||||
title: Datasource-Managed Alerts with vmalert and Grafana
|
||||
description: "Scalable alerting topology with vmalert and Grafana."
|
||||
menu:
|
||||
docs:
|
||||
parent: "guides"
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
---
|
||||
title: OpenTelemetry
|
||||
description: "OTLP ingestion for metrics, logs, and traces in VictoriaMetrics, VictoriaLogs, and VictoriaTraces, with signal correlation and configuration guides."
|
||||
weight: 60
|
||||
menu:
|
||||
docs:
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
---
|
||||
title: Playgrounds
|
||||
description: "Public demo environments for VictoriaMetrics, VictoriaLogs, and VictoriaTraces."
|
||||
weight: 63
|
||||
menu:
|
||||
docs:
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
---
|
||||
weight: 29
|
||||
title: Articles
|
||||
description: "Third-party articles, slides, and videos about VictoriaMetrics."
|
||||
menu:
|
||||
docs:
|
||||
parent: 'victoriametrics'
|
||||
@@ -156,13 +157,6 @@ See [our blog](https://victoriametrics.com/blog) for the latest articles written
|
||||
* [Why irate from Prometheus doesn't capture spikes](https://valyala.medium.com/why-irate-from-prometheus-doesnt-capture-spikes-45f9896d7832)
|
||||
* [VictoriaMetrics: PromQL compliance](https://medium.com/@romanhavronenko/victoriametrics-promql-compliance-d4318203f51e)
|
||||
* [How do open source solutions for logs work: Elasticsearch, Loki and VictoriaLogs](https://itnext.io/how-do-open-source-solutions-for-logs-work-elasticsearch-loki-and-victorialogs-9f7097ecbc2f)
|
||||
* [How vmagent Collects and Ships Metrics Fast with Aggregation, Deduplication, and More](https://victoriametrics.com/blog/vmagent-how-it-works/)
|
||||
* [When Metrics Meet vminsert: A Data-Delivery Story](https://victoriametrics.com/blog/vminsert-how-it-works/)
|
||||
* [How vmstorage Handles Data Ingestion From vminsert](https://victoriametrics.com/blog/vmstorage-how-it-handles-data-ingestion/)
|
||||
* [How vmstorage Processes Data: Retention, Merging, Deduplication...](https://victoriametrics.com/blog/vmstorage-retention-merging-deduplication/)
|
||||
* [How vmstorage's IndexDB Works](https://victoriametrics.com/blog/vmstorage-how-indexdb-works/)
|
||||
* [How vmstorage Handles Query Requests From vmselect](https://victoriametrics.com/blog/vmstorage-how-it-handles-query-requests/)
|
||||
* [Inside vmselect: The Query Processing Engine of VictoriaMetrics](https://victoriametrics.com/blog/vmselect-how-it-works/)
|
||||
|
||||
### Tutorials, guides and how-to articles
|
||||
|
||||
@@ -180,12 +174,6 @@ See [our guides](https://docs.victoriametrics.com/guides/) for the up-to-date gu
|
||||
* [Prometheus storage: tech terms for humans](https://valyala.medium.com/prometheus-storage-technical-terms-for-humans-4ab4de6c3d48)
|
||||
* [Cardinality explorer](https://victoriametrics.com/blog/cardinality-explorer/)
|
||||
* [Rules backfilling via vmalert](https://victoriametrics.com/blog/rules-replay/)
|
||||
* [vmagent: Key Features Explained in Under 15 Minutes](https://victoriametrics.com/blog/vmagent-key-features-explained/)
|
||||
* [Prometheus Metrics Explained: Counters, Gauges, Histograms & Summaries](https://victoriametrics.com/blog/prometheus-monitoring-metrics-counters-gauges-histogram-summaries/)
|
||||
* [Prometheus Monitoring: Instant Queries and Range Queries Explained](https://victoriametrics.com/blog/prometheus-monitoring-instant-range-query/)
|
||||
* [Prometheus Monitoring: Functions, Subqueries, Operators, and Modifiers](https://victoriametrics.com/blog/prometheus-monitoring-function-operator-modifier/)
|
||||
* [Prometheus Alerting 101: Rules, Recording Rules, and Alertmanager](https://victoriametrics.com/blog/alerting-recording-rules-alertmanager/)
|
||||
* [Alerting Best Practices](https://victoriametrics.com/blog/alerting-best-practices/)
|
||||
|
||||
### Other articles
|
||||
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
---
|
||||
weight: 22
|
||||
title: Best practices
|
||||
description: "Production best practices for installation, configuration, hardware sizing, and maintenance."
|
||||
menu:
|
||||
docs:
|
||||
identifier: vm-best-practices
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
---
|
||||
weight: 400
|
||||
title: Contributing
|
||||
description: "Guidelines for contributing to VictoriaMetrics."
|
||||
menu:
|
||||
docs:
|
||||
identifier: vm-contributing
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
---
|
||||
weight: 25
|
||||
title: Case studies and talks
|
||||
description: "Production case studies from Grammarly, Roblox, Wix, Spotify, adidas, and more."
|
||||
menu:
|
||||
docs:
|
||||
parent: "victoriametrics"
|
||||
|
||||
@@ -6,6 +6,7 @@ menu:
|
||||
parent: 'victoriametrics'
|
||||
weight: 2
|
||||
title: Cluster version
|
||||
description: "Deploy and configure cluster mode with vminsert, vmselect, and vmstorage components, including replication and multi-tenancy."
|
||||
tags:
|
||||
- metrics
|
||||
aliases:
|
||||
@@ -59,11 +60,6 @@ It increases cluster availability, and simplifies cluster maintenance as well as
|
||||
|
||||

|
||||
|
||||
> Further reading, deep dives into how each service works internally:
|
||||
> - `vmstorage`: [How vmstorage Handles Data Ingestion From vminsert](https://victoriametrics.com/blog/vmstorage-how-it-handles-data-ingestion/), [How vmstorage's IndexDB Works](https://victoriametrics.com/blog/vmstorage-how-indexdb-works/), [How vmstorage Handles Query Requests From vmselect](https://victoriametrics.com/blog/vmstorage-how-it-handles-query-requests/).
|
||||
> - `vminsert`: [When Metrics Meet vminsert: A Data-Delivery Story](https://victoriametrics.com/blog/vminsert-how-it-works/).
|
||||
> - `vmselect`: [Inside vmselect: The Query Processing Engine of VictoriaMetrics](https://victoriametrics.com/blog/vmselect-how-it-works/).
|
||||
|
||||
## vmui
|
||||
|
||||
VictoriaMetrics cluster version provides UI for query troubleshooting and exploration. The UI is available at
|
||||
@@ -100,7 +96,7 @@ See also multitenancy [via headers](#multitenancy-via-headers) and [via labels](
|
||||
|
||||
### Multitenancy via headers
|
||||
|
||||
With `--enableMultitenancyViaHeaders` {{% available_from "v1.143.0" %}} command-line flag enabled (enabled by default {{% available_from "v1.150.0" %}})
|
||||
With `--enableMultitenancyViaHeaders` {{% available_from "v1.143.0" %}} command-line flag enabled (enabled by default {{% available_from "#" %}})
|
||||
tenant ID can be specified via HTTP headers `AccountID` and `ProjectID`. This flag needs to be enabled on vminserts and vmselects.
|
||||
|
||||
With `--enableMultitenancyViaHeaders` enabled [URL format](#url-format) can be simplified to the following:
|
||||
@@ -833,8 +829,8 @@ See also [minimum downtime strategy](#minimum-downtime-strategy).
|
||||
|
||||
## Slowness-based re-routing
|
||||
|
||||
By default{{% available_from "v1.149.0" %}}, `vminsert` automatically [re-route writes](https://victoriametrics.com/blog/vminsert-how-it-works/#31-rerouting)
|
||||
away from the slowest `vmstorage` node to preserve maximum ingestion throughput. This prevents a single slow `vmstorage` node
|
||||
By default{{% available_from "v1.149.0" %}}, `vminsert` automatically re-routes writes away from the slowest `vmstorage` node
|
||||
to preserve maximum ingestion throughput. This prevents a single slow `vmstorage` node
|
||||
from throttling the entire cluster.
|
||||
|
||||
Re-routing occurs only when all of the following conditions hold:
|
||||
@@ -882,7 +878,7 @@ See also [resource usage limits docs](#resource-usage-limits).
|
||||
|
||||
## Rebalancing
|
||||
|
||||
Every `vminsert` node [evenly spreads (shards) incoming data](https://victoriametrics.com/blog/vminsert-how-it-works/#3-sharding-and-buffering) among `vmstorage` nodes specified in the `-storageNode` command-line flag.
|
||||
Every `vminsert` node evenly spreads (shards) incoming data among `vmstorage` nodes specified in the `-storageNode` command-line flag.
|
||||
This guarantees even distribution of the ingested data among `vmstorage` nodes. When new `vmstorage` nodes are added to the `-storageNode`
|
||||
command-line flag at `vminsert`, then only newly ingested data is distributed evenly among old and new `vmstorage` nodes, while
|
||||
historical data remains on the old `vmstorage` nodes. This speeds up data ingestion and querying for the majority of production workloads,
|
||||
@@ -1030,7 +1026,7 @@ By default, VictoriaMetrics offloads replication to the underlying storage point
|
||||
which guarantees data durability. VictoriaMetrics supports application-level replication if replicated durable persistent disks cannot be used for some reason.
|
||||
|
||||
The replication can be enabled by passing `-replicationFactor=N` command-line flag to `vminsert`. This instructs `vminsert` to store `N` copies for every ingested sample
|
||||
on `N` distinct `vmstorage` nodes. This guarantees that all the stored data remains available for querying if up to `N-1` `vmstorage` nodes are unavailable. See [how `vminsert` replicates each sample to `N` `vmstorage` nodes](https://victoriametrics.com/blog/vminsert-how-it-works/#4-replication-and-sending-data-to-vmstorage) for details.
|
||||
on `N` distinct `vmstorage` nodes. This guarantees that all the stored data remains available for querying if up to `N-1` `vmstorage` nodes are unavailable.
|
||||
|
||||
Passing `-replicationFactor=N` command-line flag to `vmselect` instructs it to not mark responses as `partial` if less than `-replicationFactor` vmstorage nodes are unavailable during the query.
|
||||
See [cluster availability docs](#cluster-availability) for details.
|
||||
@@ -1065,7 +1061,7 @@ deduplication can't be guaranteed when samples and sample duplicates for the sam
|
||||
- when `vmstorage` node has no enough capacity for processing incoming data stream. Then `vminsert` re-routes new samples to other `vmstorage` nodes.
|
||||
|
||||
It is recommended to set **the same** `-dedup.minScrapeInterval` command-line flag value to both `vmselect` and `vmstorage` nodes
|
||||
to ensure query results consistency, even if [storage layer didn't complete deduplication](https://victoriametrics.com/blog/vmstorage-retention-merging-deduplication/#deduplication) yet.
|
||||
to ensure query results consistency, even if storage layer didn't complete deduplication yet.
|
||||
|
||||
## Metrics Metadata
|
||||
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
---
|
||||
weight: 24
|
||||
title: FAQ
|
||||
description: "Frequently asked questions comparing VM with Prometheus, InfluxDB, TimescaleDB, M3DB, Thanos, and Cortex."
|
||||
menu:
|
||||
docs:
|
||||
parent: 'victoriametrics'
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
---
|
||||
weight: 300
|
||||
title: Long-term support releases
|
||||
description: "Long-term support release lines for enterprise customers."
|
||||
menu:
|
||||
docs:
|
||||
parent: 'victoriametrics'
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
---
|
||||
weight: 23
|
||||
title: MetricsQL
|
||||
description: "Query language reference. Enhanced PromQL with additional functions, histogram helpers, and subquery support."
|
||||
menu:
|
||||
docs:
|
||||
parent: 'victoriametrics'
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
---
|
||||
weight: 81
|
||||
title: Cluster Per Tenant Statistic
|
||||
description: "Enterprise cluster per-tenant usage tracking."
|
||||
menu:
|
||||
docs:
|
||||
identifier: vm-cluster-per-tenant-statistic
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
---
|
||||
weight: 1
|
||||
title: Quick start
|
||||
description: "Get up and running with VictoriaMetrics. Download, run, scrape, and query."
|
||||
menu:
|
||||
docs:
|
||||
identifier: vm-quick-start
|
||||
|
||||
@@ -1407,9 +1407,6 @@ for fast block lookups, which belong to the given `TSID` and cover the given tim
|
||||
* various background maintenance tasks such as [de-duplication](#deduplication), [downsampling](#downsampling)
|
||||
and [freeing up disk space for the deleted time series](#how-to-delete-time-series) are performed during the merge
|
||||
|
||||
See how `vmstorage` [selects parts for background merging](https://victoriametrics.com/blog/vmstorage-retention-merging-deduplication/#merge-process),
|
||||
including merge limits and monitoring metrics.
|
||||
|
||||
Newly added `parts` either successfully appear in the storage or fail to appear.
|
||||
The newly added `part` is atomically registered in the `parts.json` file under the corresponding partition
|
||||
after it is fully written and [fsynced](https://man7.org/linux/man-pages/man2/fsync.2.html) to the storage.
|
||||
@@ -1537,8 +1534,6 @@ are **eventually deleted** during [background merge](https://medium.com/@valyala
|
||||
The time range covered by data part is **not limited by retention period unit**. One data part can cover hours or days of
|
||||
data. Hence, a data part can be deleted only **when fully outside the configured retention**.
|
||||
See more about partitions and parts in the [Storage section](#storage).
|
||||
See how the [retention and free-disk watchers manage storage](https://victoriametrics.com/blog/vmstorage-retention-merging-deduplication/#retention-free-disk-space-guard-and-downsampling)
|
||||
for implementation details and monitoring metrics.
|
||||
|
||||
The maximum disk space usage for a given `-retentionPeriod` is going to be (`-retentionPeriod` + 1) months.
|
||||
For example, if `-retentionPeriod` is set to 1, data for January is deleted on March 1st.
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
---
|
||||
weight: 501
|
||||
title: Release process guidance
|
||||
description: "Guidance for preparing, testing, and publishing VictoriaMetrics releases."
|
||||
menu:
|
||||
docs:
|
||||
parent: 'victoriametrics'
|
||||
|
||||
@@ -6,6 +6,7 @@ menu:
|
||||
parent: victoriametrics
|
||||
weight: 1
|
||||
title: Single-node version
|
||||
description: "Deploy and configure the single-node version, including CLI flags, storage, and HTTP API."
|
||||
tags:
|
||||
- metrics
|
||||
aliases:
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
---
|
||||
weight: 35
|
||||
title: Troubleshooting
|
||||
description: "Common issues. High memory usage, slow queries, cardinality problems, ingestion failures."
|
||||
menu:
|
||||
docs:
|
||||
parent: 'victoriametrics'
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
---
|
||||
title: VictoriaMetrics
|
||||
description: "Fast, cost-effective, and scalable time series database for monitoring and managing metrics data."
|
||||
menu:
|
||||
docs:
|
||||
weight: 10
|
||||
|
||||
@@ -26,16 +26,8 @@ See also [LTS releases](https://docs.victoriametrics.com/victoriametrics/lts-rel
|
||||
|
||||
## tip
|
||||
|
||||
## [v1.150.0](https://github.com/VictoriaMetrics/VictoriaMetrics/releases/tag/v1.150.0)
|
||||
|
||||
Release candidate
|
||||
|
||||
**Update Note 1:** `vmselect` and `vminsert` in [VictoriaMetrics cluster](https://docs.victoriametrics.com/victoriametrics/cluster-victoriametrics/), and `vmagent`: default value of `-enableMultitenancyViaHeaders` command-line flag has changed from `false` to `true`. This change enables support of [multitenancy via headers for cluster](https://docs.victoriametrics.com/victoriametrics/cluster-victoriametrics/#multitenancy-via-headers) and [for vmagent](https://docs.victoriametrics.com/victoriametrics/vmagent/#multitenancy-via-headers) by default. With this change, mentioned components will start supporting URLs with omitted tenant ID in the path: `https://<vmselect>:8481/select/prometheus/api/v1/query` will become a valid URL. To disable multitenancy via headers and simplified URLs set `--enableMultitenancyViaHeaders=false` on vmagent, vminsert and vmselect.
|
||||
|
||||
* SECURITY: upgrade Go builder from Go1.26.5 to Go1.26.6. See [the list of issues addressed in Go1.26.6](https://github.com/golang/go/issues?q=milestone%3AGo1.26.6%20label%3ACherryPickApproved).
|
||||
|
||||
* FEATURE: [relabeling](https://docs.victoriametrics.com/victoriametrics/relabeling/): reduce CPU usage up to 30% when matching relabeling rules with multiple `if` expressions containing exact metric names. Expressions for other metric names are now skipped before evaluating their remaining label filters. See [#11341](https://github.com/VictoriaMetrics/VictoriaMetrics/pull/11341). Thanks to @nevgeny for contribution.
|
||||
* FEATURE: [vmagent](https://docs.victoriametrics.com/victoriametrics/vmagent/) and [vmsingle](https://docs.victoriametrics.com/victoriametrics/single-server-victoriametrics/): add support for [linode_sd_configs](https://docs.victoriametrics.com/victoriametrics/sd_configs/#linode_sd_configs) for discovering scrape targets from Linode instances. See [#9118](https://github.com/VictoriaMetrics/VictoriaMetrics/issues/9118). Thanks to @cxdy for contribution.
|
||||
* FEATURE: [vmalert](https://docs.victoriametrics.com/victoriametrics/vmalert/): extend `-replay.continueWithExecutionErr` to also handle the `400 Bad Request` response code, since it is used for Prometheus querying API requests when request parameters are missing or incorrect. See [#11352](https://github.com/VictoriaMetrics/VictoriaMetrics/pull/11352).
|
||||
* FEATURE: `vmselect` and `vminsert` in [VictoriaMetrics cluster](https://docs.victoriametrics.com/victoriametrics/cluster-victoriametrics/), and `vmagent`: set default value of `-enableMultitenancyViaHeaders` to `true`. This change enables support of [multitenancy via headers for cluster](https://docs.victoriametrics.com/victoriametrics/cluster-victoriametrics/#multitenancy-via-headers) and [for vmagent](https://docs.victoriametrics.com/victoriametrics/vmagent/#multitenancy-via-headers) by default, aligning VictoriaMetrics multitenancy behavior with [multitenancy in VictoriaLogs](https://docs.victoriametrics.com/victorialogs/#multitenancy). See related ticket [#11365](https://github.com/VictoriaMetrics/VictoriaMetrics/issues/11365).
|
||||
* FEATURE: [vmui](https://docs.victoriametrics.com/victoriametrics/single-server-victoriametrics/#vmui): add an option to customize the favicon color. This makes it easier to distinguish between different installations opened in multiple browser tabs. See [#11329](https://github.com/VictoriaMetrics/VictoriaMetrics/issues/11329).
|
||||
@@ -43,13 +35,9 @@ Release candidate
|
||||
* BUGFIX: [vmagent](https://docs.victoriametrics.com/victoriametrics/vmagent/) and [vmsingle](https://docs.victoriametrics.com/victoriametrics/single-server-victoriametrics/): avoid suggesting the unrelated `-enableTCP6` command-line flag when scraping a target over a Unix domain socket fails. See [#11320](https://github.com/VictoriaMetrics/VictoriaMetrics/pull/11320). Thanks to @lwmacct for contribution.
|
||||
* BUGFIX: [vmsingle](https://docs.victoriametrics.com/victoriametrics/single-server-victoriametrics/) and `vminsert` in [VictoriaMetrics cluster](https://docs.victoriametrics.com/victoriametrics/cluster-victoriametrics/): skip labels with empty name at [/api/v1/import](https://docs.victoriametrics.com/victoriametrics/#how-to-import-data-in-json-line-format). Previously such a label replaced the metric name, so a series sent with `"metric":{"__name__":"foo","":"bar"}` was stored under the name `bar`. Other ingestion protocols already skip such labels. See [#4962](https://github.com/VictoriaMetrics/VictoriaMetrics/issues/4962). Thanks to @Vandit1604 for contribution.
|
||||
* BUGFIX: [vmsingle](https://docs.victoriametrics.com/victoriametrics/single-server-victoriametrics/), `vmselect` in [VictoriaMetrics cluster](https://docs.victoriametrics.com/victoriametrics/cluster-victoriametrics/) and [vmctl](https://docs.victoriametrics.com/victoriametrics/vmctl/): properly parse small fractional Unix timestamps in timestamp args such as `start` and `end` in `/api/v1/query_range` and `--vm-native-filter-time-start` and `--vm-native-filter-time-end` in `vmctl`. Previously, fractional Unix timestamps with the integer part below `9223372` were interpreted with the wrong unit, for example `12.0` was parsed as `12000` seconds instead of `12` seconds. See [#11324](https://github.com/VictoriaMetrics/VictoriaMetrics/issues/11324).
|
||||
* BUGFIX: [vmsingle](https://docs.victoriametrics.com/victoriametrics/single-server-victoriametrics/), `vmstorage` and `vmselect` in [VictoriaMetrics cluster](https://docs.victoriametrics.com/victoriametrics/cluster-victoriametrics/): persist the previous working set cache during graceful shutdown when it is likely to contain the active working set. This prevents saving an empty or cold current cache right after split-mode cache rotation, which could otherwise slow down ingestion or queries after restart until the cache warms up again. See [#11299](https://github.com/VictoriaMetrics/VictoriaMetrics/issues/11299).
|
||||
* BUGFIX: [vmsingle](https://docs.victoriametrics.com/victoriametrics/single-server-victoriametrics/) and `vmselect` in [VictoriaMetrics cluster](https://docs.victoriametrics.com/victoriametrics/cluster-victoriametrics/): change the HTTP response code for [Prometheus querying API](https://docs.victoriametrics.com/victoriametrics/single-server-victoriametrics/#prometheus-querying-api-usage) requests from `422 Unprocessable Entity` to `400 Bad Request` when request parameters are missing or incorrect. See [#11330](https://github.com/VictoriaMetrics/VictoriaMetrics/issues/11330).
|
||||
* BUGFIX: [vmui](https://docs.victoriametrics.com/victoriametrics/single-server-victoriametrics/#vmui): respect the custom query step specified via `g0.step_input` when opening a URL. Previously, it could be reset to the automatically calculated step and potentially cause dashboards to freeze. See [#11137](https://github.com/VictoriaMetrics/VictoriaMetrics/issues/11137).
|
||||
* BUGFIX: [vmagent](https://docs.victoriametrics.com/victoriametrics/vmagent/) and [vmsingle](https://docs.victoriametrics.com/victoriametrics/single-server-victoriametrics/): properly assign scrape target IP address at IPv6-only networks for [docker_sd_configs](https://docs.victoriametrics.com/victoriametrics/sd_configs/#docker_sd_configs). See [#10965](https://github.com/VictoriaMetrics/VictoriaMetrics/issues/10965).
|
||||
* BUGFIX: [vmalert](https://docs.victoriametrics.com/victoriametrics/vmalert/): rename `vmalert_rule_group_results_limit` back to `vmalert_group_rule_results_limit`. The metric was introduced in [v1.147.0](https://docs.victoriametrics.com/victoriametrics/changelog/#v11470) but was accidentally given the wrong name. See [#11179](https://github.com/VictoriaMetrics/VictoriaMetrics/issues/11179).
|
||||
* BUGFIX: [vmalert](https://docs.victoriametrics.com/victoriametrics/vmalert/): properly update group-level `eval_delay` and `eval_alignment` for existing groups during runtime when config reload is triggered periodically or manually via `/-/reload`. Previously, these settings weren't updated after config reload during runtime. See [#11374](https://github.com/VictoriaMetrics/VictoriaMetrics/issues/11374).
|
||||
* BUGFIX: `vmselect` in [VictoriaMetrics cluster](https://docs.victoriametrics.com/victoriametrics/cluster-victoriametrics/): scale the default `-search.maxConcurrentRequests` with the number of available CPU cores instead of capping it at 16. See [#11191](https://github.com/VictoriaMetrics/VictoriaMetrics/issues/11191). Thanks to @Dhru1Tanna for contribution.
|
||||
|
||||
## [v1.149.0](https://github.com/VictoriaMetrics/VictoriaMetrics/releases/tag/v1.149.0)
|
||||
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
---
|
||||
weight: 8
|
||||
title: Year 2020
|
||||
description: "Release history for all VictoriaMetrics components (YEAR 2020)"
|
||||
search:
|
||||
weight: 0.1
|
||||
menu:
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
---
|
||||
weight: 7
|
||||
title: Year 2021
|
||||
description: "Release history for all VictoriaMetrics components (YEAR 2021)"
|
||||
search:
|
||||
weight: 0.1
|
||||
menu:
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
---
|
||||
weight: 6
|
||||
title: Year 2022
|
||||
description: "Release history for all VictoriaMetrics components (YEAR 2022)"
|
||||
search:
|
||||
weight: 0.1
|
||||
menu:
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
---
|
||||
weight: 5
|
||||
title: Year 2023
|
||||
description: "Release history for all VictoriaMetrics components (YEAR 2023)"
|
||||
search:
|
||||
weight: 0.1
|
||||
menu:
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
---
|
||||
weight: 4
|
||||
title: Year 2024
|
||||
description: "Release history for all VictoriaMetrics components (YEAR 2024)"
|
||||
search:
|
||||
weight: 0.1
|
||||
menu:
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
---
|
||||
weight: 3
|
||||
title: Year 2025
|
||||
description: "Release history for all VictoriaMetrics components (YEAR 2025)"
|
||||
search:
|
||||
weight: 0.1
|
||||
menu:
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
---
|
||||
weight: 2
|
||||
title: Year 2026
|
||||
description: "Release history for all VictoriaMetrics components (YEAR 2026)"
|
||||
search:
|
||||
weight: 0.1
|
||||
menu:
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
---
|
||||
weight: 100
|
||||
title: CHANGELOG
|
||||
description: "Release history for all VictoriaMetrics components."
|
||||
menu:
|
||||
docs:
|
||||
identifier: vm-changelog
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
---
|
||||
title: Grafana Alloy
|
||||
description: "Configure Grafana Alloy to send metrics to VictoriaMetrics."
|
||||
weight: 3
|
||||
menu:
|
||||
docs:
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
---
|
||||
title: OpenTelemetry Collector
|
||||
description: "Configure OTel Collector with OTLP HTTP exporter."
|
||||
weight: 7
|
||||
menu:
|
||||
docs:
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
---
|
||||
title: Proxmox
|
||||
description: "Send Proxmox VE/PBS metrics to VictoriaMetrics."
|
||||
weight: 6
|
||||
menu:
|
||||
docs:
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
---
|
||||
title: Telegraf
|
||||
description: "Configure Telegraf to ship metrics to VictoriaMetrics."
|
||||
weight: 5
|
||||
menu:
|
||||
docs:
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
---
|
||||
title: Vector
|
||||
description: "Configure Vector with Prometheus remote write sink."
|
||||
weight: 4
|
||||
menu:
|
||||
docs:
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
---
|
||||
title: Data Ingestion
|
||||
description: "Supported ingestion protocols. Prometheus remote write, InfluxDB, Graphite, OpenTSDB, Datadog, New Relic, OpenTelemetry, CSV, JSON, and native binary."
|
||||
weight: 0
|
||||
menu:
|
||||
docs:
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
---
|
||||
title: vmagent
|
||||
description: "Using vmagent as a data ingestion agent."
|
||||
weight: 2
|
||||
menu:
|
||||
docs:
|
||||
|
||||