{"id":72093,"date":"2026-06-09T13:17:29","date_gmt":"2026-06-09T05:17:29","guid":{"rendered":"https:\/\/oihelp.corporate.ifs.com\/help\/?page_id=72093"},"modified":"2026-07-28T11:58:36","modified_gmt":"2026-07-28T03:58:36","slug":"anomaly-detection","status":"publish","type":"page","link":"https:\/\/oihelp.corporate.ifs.com\/help\/sentinel\/sentinel-processes\/anomaly-detection\/","title":{"rendered":"Anomaly Detection Process"},"content":{"rendered":"\n<p class=\"left-bar\">This article applies to versions 26R1 and later of IFS OI Sentinel. The Anomaly Detection process is currently available only in IFS Cloud OI Sentinel.<\/p>\n<p class=\"intro-text\">The Anomaly Detection process is used for testing continuous data for a monitor item. The sample data is analysed over time using machine learning to identify unusual patterns and behaviour.<\/p>\n<p class=\"intro-text\">The process evaluates one or more inputs from entity attributes and detects anomalies based on patterns observed in historical data. Instead of comparing data against fixed limits, the process identifies data points that deviate from expected behaviour.<\/p>\n<p class=\"no-toc-heading\" style=\"font-size: 30px !important;\">Events<\/p>\n<p class=\"intro-text\">When a new state is reached, an event is raised. The severity for that state is specified in the state configuration panel of the test.<\/p>\n<p class=\"no-toc-heading\" style=\"font-size: 30px !important;\">Behaviour<\/p>\n<p class=\"intro-text\">The Anomaly Detection process evaluates time-series data collected for each configured input and identifies anomalies based on learned patterns.<\/p>\n<p class=\"no-toc-heading\" style=\"font-size: 20px !important;\">Initial Data Requirement<\/p>\n<p class=\"intro-text\">At least 512 data points per input are required before anomaly detection begins. Until this requirement is met, no anomaly detection occurs and no state or event changes are triggered.<\/p>\n<p class=\"intro-text\">As an example, if the Test is configured with a 1-minute sample interval, the first 512 non-suppressed data points will not produce any anomaly detection results. The process will begin evaluating data only after sufficient data has been collected, using a set of recently collected data that includes previously captured values.<\/p>\n<p class=\"no-toc-heading\" style=\"font-size: 20px !important;\">Data Evaluation<\/p>\n<p class=\"intro-text\">Once sufficient data is available, the process evaluates the input data to identify unusual behaviour based on the selected model.<\/p>\n<p class=\"intro-text\">The evaluation results are used to determine the current state of the monitor item and trigger events where applicable.<\/p>\n<p class=\"no-toc-heading\" style=\"font-size: 20px !important;\">Detection Accuracy<\/p>\n<p class=\"intro-text\">Initial results may be less reliable due to the smaller dataset.<\/p>\n<p class=\"intro-text\">As more data is collected, the detection accuracy improves and false positives are reduced.<\/p>\n<p class=\"no-toc-heading\" style=\"font-size: 20px !important;\">Data Limits<\/p>\n<p class=\"intro-text\">The process enforces an upper limit on the amount of data used for evaluation:<\/p>\n<ul class=\"intro-text\">\n<li>Maximum 1,000,000 data points across all inputs.<\/li>\n<li>For multiple inputs, data is distributed across inputs. For example, for 10 inputs specified, a maximum of 100,000 points per input window is used.<\/li>\n<\/ul>\n<hr \/>\n<h2 class=\"page-subheading\">Inputs<\/h2>\n<div>\n<p class=\"intro-text\">The Anomaly Detection process allows configuration of multiple inputs.<\/p>\n<ul class=\"intro-text\">\n<li>Minimum: 1 input<\/li>\n<li>Maximum: 100 inputs<\/li>\n<\/ul>\n<p class=\"intro-text\">The primary input is based on the selected Source context, while additional inputs can be configured to supplement the analysis.<\/p>\n<p class=\"intro-text\">Inputs can be defined using attributes, calculations, tags, entity attributes, or fixed values.<\/p>\n<p class=\"intro-text\">Each configured input provides data values that are evaluated by the anomaly detection process.<\/p>\n<p class=\"left-bar-blue\">Read more: <a href=\"#Adding_an_Anomaly_Detection_Process\">Adding an Anomaly Detection Process<\/a><\/p>\n<hr \/>\n<h2 class=\"page-subheading\">Machine Learning Model<\/h2>\n<p class=\"intro-text\">The Anomaly Detection process uses machine learning to analyse input data. A model can be selected in the <strong>Model Settings<\/strong> section in the Process Panel.<\/p>\n<p><a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2026\/06\/model-settings.png\" rel=\"lightbox-0\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone  wp-image-72163\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2026\/06\/model-settings-1080x181.png\" alt=\"\" width=\"741\" height=\"124\" srcset=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2026\/06\/model-settings-1080x181.png 1080w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2026\/06\/model-settings-600x101.png 600w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2026\/06\/model-settings-150x25.png 150w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2026\/06\/model-settings-768x129.png 768w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2026\/06\/model-settings-48x8.png 48w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2026\/06\/model-settings.png 1125w\" sizes=\"auto, (max-width: 741px) 100vw, 741px\" \/><\/a><\/p>\n<p class=\"no-toc-heading\" style=\"font-size: 20px !important;\">Available Models<\/p>\n<p class=\"intro-text\">The following model is supported for the Anomaly Detection process:<\/p>\n<ul class=\"intro-text\">\n<li>IFS.ai Unsupervised (Low)<\/li>\n<\/ul>\n<p class=\"intro-text\">This model provides a basic level of anomaly detection.<\/p>\n<p class=\"note\">Note: Only one machine learning model is currently available in this process. Additional models and configuration options are expected to be introduced in future releases.<\/p>\n<\/div>\n<hr \/>\n<h2 class=\"page-subheading\">State Transition Rules<\/h2>\n<p class=\"intro-text\">The Anomaly Detection process determines state transitions based on the evaluation of input data. Transition from one state to another is equally dependent on the current evaluation of data, and on the current state.\u00a0<\/p>\n<p class=\"intro-text\">State transitions cause events to be raised, allowing for the escalation of actions via the Sentinel framework. Different actions can be defined for each state outcome.<\/p>\n<p class=\"intro-text\">In the Anomaly Detection process, the state transitions are based on whether the evaluated data is identified as normal or anomalous.<\/p>\n<p class=\"intro-text\">For example, the Default state can transition to the Anomalous state when unusual behaviour is detected, and can return to the Default state when the data is considered normal again.<\/p>\n<hr \/>\n<h2 class=\"page-subheading\">Test Outcomes<\/h2>\n<p class=\"intro-text\">The following outcomes are possible when the Anomaly Detection process is executed:<\/p>\n<table>\n<tbody class=\"intro-text\">\n<tr style=\"border: 1px solid #cccccc;\">\n<td><strong>Default State<\/strong><\/td>\n<td>Data is not in an erroneous state and does not exhibit unusual behaviour.<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td><strong>Anomalous State<\/strong><\/td>\n<td>Data is identified as anomalous based on the model evaluation.<\/td>\n<\/tr>\n<tr style=\"border: 1px solid #cccccc;\">\n<td><strong>Suppressed State<\/strong><\/td>\n<td>The monitor has been suppressed. For example, if the precondition has not been met.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<hr \/>\n<h2 class=\"page-subheading\">Adding an Anomaly Detection Process<\/h2>\n<p class=\"intro-text\">Every test uses a specific type of process to evaluate monitor item data. The Anomaly Detection Process is used for testing continuous data using machine learning.<\/p>\n<p class=\"intro-text\">In the <strong>Test<\/strong> page:<\/p>\n<p class=\"intro-text\">1. Expand the <strong>Process<\/strong> <img loading=\"lazy\" decoding=\"async\" width=\"15\" height=\"16\" class=\"wp-image-60320\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2023\/03\/word-image-58865-33.png\" \/> panel.<\/p>\n<p class=\"intro-text\">The <strong>Process<\/strong> panel appears as shown in the following screen image:<\/p>\n<p class=\"intro-text\"><a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2026\/06\/AD-Process-1.png\" rel=\"lightbox-1\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone  wp-image-72171\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2026\/06\/AD-Process-1-1080x698.png\" alt=\"\" width=\"701\" height=\"453\" srcset=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2026\/06\/AD-Process-1-1080x698.png 1080w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2026\/06\/AD-Process-1-600x388.png 600w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2026\/06\/AD-Process-1-150x97.png 150w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2026\/06\/AD-Process-1-768x496.png 768w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2026\/06\/AD-Process-1-48x31.png 48w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2026\/06\/AD-Process-1.png 1127w\" sizes=\"auto, (max-width: 701px) 100vw, 701px\" \/><\/a><\/p>\n<p class=\"intro-text\">2. In the <strong>Process<\/strong> drop-down list, select <strong>Anomaly Detection<\/strong>.<\/p>\n<p class=\"intro-text\">3. From the <strong>Input<\/strong> drop-down list, select an input.<\/p>\n<p class=\"intro-text\">Each test requires a primary input (Input 1) and allows additional inputs to be configured.<\/p>\n<p class=\"intro-text\"><strong>Primary Input (Input 1):<\/strong><\/p>\n<p class=\"intro-text\">The primary input is derived from the selected Source context. Depending on the Source Type, you can select an attribute or a source tag, or define a calculation based on the monitor items. This input is used as the main data input for the process.<\/p>\n<p class=\"intro-text\"><strong>Additional Inputs:<\/strong><\/p>\n<p class=\"intro-text\">Additional inputs can be configured, up to a maximum of 100 inputs in total. These inputs can be defined using the available input options and are used to supplement the analysis.<\/p>\n<p class=\"no-toc-heading\" style=\"font-size: 20px !important;\">Input Types<\/p>\n<p class=\"intro-text\"><strong>Attribute<\/strong>: This option is only available if the <strong>Source Type<\/strong> is <strong>Entity <\/strong>or<strong> Hierarchy<\/strong>. <br \/>\nClick the ellipsis <img loading=\"lazy\" decoding=\"async\" width=\"22\" height=\"24\" class=\"wp-image-60322\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2023\/03\/word-image-58865-35.png\" \/> button to select an attribute. You are limited to selecting an attribute of the test source monitor items. This attribute of each of the monitor items is a separate process input.<\/p>\n<p class=\"intro-text\"><strong>Source Tag<\/strong>: This option is only available if the <strong>Source Type<\/strong> is <strong>Tag<\/strong>. If you select this option, then each of the tag monitor items is used as separate process input.<\/p>\n<p class=\"intro-text\"><strong>Calculation<\/strong>: Click the ellipsis <img loading=\"lazy\" decoding=\"async\" width=\"22\" height=\"24\" class=\"wp-image-60323\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2023\/03\/word-image-58865-36.png\" \/> button to open the Edit Calculation window.\u00a0<\/p>\n<ul class=\"intro-text\">\n<li class=\"intro-text\">If the Source Type is <strong>Entity<\/strong> or <strong>Hierarchy<\/strong>: Type a calculation, prefixed by \u2018this\u2019 as the <strong>Source Entity<\/strong> token, for example: <strong>{this:THP} + 34<\/strong>.<\/li>\n<li class=\"intro-text\">If the Source Type is <strong>Tag<\/strong>: Type a calculation, prefixed by \u2018this\u2019 as the <strong>Source<\/strong> <strong>Tag<\/strong> token, for example: <strong>{this} * 2<\/strong>.<\/li>\n<\/ul>\n<p class=\"intro-text\"><strong>Entity Attribute<\/strong>: Click the ellipsis <img loading=\"lazy\" decoding=\"async\" width=\"22\" height=\"24\" class=\"wp-image-60324\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2023\/03\/word-image-58865-37.png\" \/> button to select an entity. From here, select an attribute, or attribute value, for the selected entity.<\/p>\n<p class=\"intro-text\"><strong>Tag<\/strong>: Click the ellipsis <img loading=\"lazy\" decoding=\"async\" width=\"22\" height=\"24\" class=\"wp-image-60328\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2023\/03\/word-image-58865-41.png\" \/> button to select a tag.<\/p>\n<p class=\"intro-text\"><strong>Fixed Value<\/strong>: Type in a numerical value. This is not an option for Input 1.<\/p>\n<p class=\"intro-text\">5. To add comments to the process panel, click the comment <img loading=\"lazy\" decoding=\"async\" width=\"23\" height=\"19\" class=\"wp-image-60325\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2023\/03\/word-image-58865-38.png\" \/> button, at the top right of the panel.<\/p>\n<hr \/>\n<h2 class=\"page-subheading\">Configuring States<\/h2>\n<p class=\"intro-text\">For the Anomaly Detection process, you can configure the following states, each with an optional state override and comments:<\/p>\n<ul class=\"intro-text\" style=\"list-style-type: square;\">\n<li>Default<\/li>\n<li>Anomalous<\/li>\n<li>Suppressed<\/li>\n<\/ul>\n<p class=\"intro-text\">You cannot change the severity of the Default state; however, you can add a state override and comments.<\/p>\n<p class=\"intro-text\"><a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2026\/06\/state-config.png\" rel=\"lightbox-2\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone  wp-image-72144\" src=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2026\/06\/state-config-1080x238.png\" alt=\"\" width=\"800\" height=\"176\" srcset=\"https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2026\/06\/state-config-1080x238.png 1080w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2026\/06\/state-config-600x132.png 600w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2026\/06\/state-config-150x33.png 150w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2026\/06\/state-config-768x169.png 768w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2026\/06\/state-config-48x11.png 48w, https:\/\/oihelp.corporate.ifs.com\/help\/wp-content\/uploads\/2026\/06\/state-config.png 1133w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/a><\/p>\n<p class=\"intro-text\">Additional options such as case management actions can be configured for each state.<\/p>\n<p class=\"left-bar-blue\">Read more: <a href=\"https:\/\/oihelp.corporate.ifs.com\/help\/sentinel\/working-with-sentinel-monitors\/add-tests-to-a-monitor\/#Configure_States\">Configure States in a Test<\/a><\/p>\n<hr \/>\n<h2 class=\"page-subheading\">Release History<\/h2>\n<ul class=\"intro-text\">\n<li>Anomaly Detection Process 26R1 (IFS Cloud Release)<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>The Anomaly Detection process is used for testing continuous data for a monitor item. The sample data is analysed over time using machine learning to identify unusual patterns and behaviour.<\/p>\n<p class=\"continue-reading-button\"> <a class=\"continue-reading-link\" href=\"https:\/\/oihelp.corporate.ifs.com\/help\/sentinel\/sentinel-processes\/anomaly-detection\/\">Read more<i class=\"crycon-right-dir\"><\/i><\/a><\/p>\n","protected":false},"author":38,"featured_media":67342,"parent":58770,"menu_order":15,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":"","_members_access_role":[],"_members_access_error":""},"categories":[9],"tags":[1321,1002,1146],"class_list":["post-72093","page","type-page","status-publish","has-post-thumbnail","hentry","category-tech-ref","tag-anomaly-detection","tag-process","tag-sentinel","Version-26r1","Product-sen"],"_links":{"self":[{"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/pages\/72093","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/users\/38"}],"replies":[{"embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/comments?post=72093"}],"version-history":[{"count":9,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/pages\/72093\/revisions"}],"predecessor-version":[{"id":72430,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/pages\/72093\/revisions\/72430"}],"up":[{"embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/pages\/58770"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/media\/67342"}],"wp:attachment":[{"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/media?parent=72093"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/categories?post=72093"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/oihelp.corporate.ifs.com\/help\/wp-json\/wp\/v2\/tags?post=72093"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}