How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Elastic Stack (ELK Stack) ml anomaly API

The ml anomaly API from Elastic Stack (ELK Stack) — 45 operation(s) for ml anomaly.

Elastic Stack (ELK Stack) ml anomaly API is one of 132 APIs that Elastic Stack (ELK Stack) publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include ml anomaly. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, and an API reference.

This API exposes 70 operations across 45 paths, and defines 624 schemas. It is described by OpenAPI 3.2.0.

Requests are made against the base URL https://{elasticsearch_endpoint}.

70 operations 45 paths 624 schemas 11 DELETE25 GET29 POST5 PUT

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
Base URL
https://{elasticsearch_endpoint}
License
Resource Areas
1

Paths & Operations 70

Across 45 paths, the API surfaces 70 operations — 11 DELETE, 25 GET, 29 POST, 5 PUT. Each is listed below with its method, path, parameters, and response codes.

ml anomaly 70
POST
/_ml/anomaly_detectors/{job_id}/_close
Close anomaly detection jobs
ml-close-job 4 params body → 200
GET
/_ml/calendars/{calendar_id}
Get calendar configuration info
ml-get-calendars-2 3 params body → 200
PUT
/_ml/calendars/{calendar_id}
Create a calendar
ml-put-calendar 1 param body → 200
POST
/_ml/calendars/{calendar_id}
Get calendar configuration info
ml-get-calendars-3 3 params body → 200
DELETE
/_ml/calendars/{calendar_id}
Delete a calendar
ml-delete-calendar 1 param → 200
DELETE
/_ml/calendars/{calendar_id}/events/{event_id}
Delete events from a calendar
ml-delete-calendar-event 2 params → 200
PUT
/_ml/calendars/{calendar_id}/jobs/{job_id}
Add anomaly detection job to calendar
ml-put-calendar-job 2 params → 200
DELETE
/_ml/calendars/{calendar_id}/jobs/{job_id}
Delete anomaly jobs from a calendar
ml-delete-calendar-job 2 params → 200
GET
/_ml/datafeeds/{datafeed_id}
Get datafeeds configuration info
ml-get-datafeeds 3 params → 200
PUT
/_ml/datafeeds/{datafeed_id}
Create a datafeed
ml-put-datafeed 5 params body → 200
DELETE
/_ml/datafeeds/{datafeed_id}
Delete a datafeed
ml-delete-datafeed 2 params → 200
DELETE
/_ml/_delete_expired_data/{job_id}
Delete expired ML data
ml-delete-expired-data 3 params body → 200
DELETE
/_ml/_delete_expired_data
Delete expired ML data
ml-delete-expired-data-1 2 params body → 200
GET
/_ml/filters/{filter_id}
Get filters
ml-get-filters-1 3 params → 200
PUT
/_ml/filters/{filter_id}
Create a filter
ml-put-filter 1 param body → 200
DELETE
/_ml/filters/{filter_id}
Delete a filter
ml-delete-filter 1 param → 200
POST
/_ml/anomaly_detectors/{job_id}/_forecast
Predict future behavior of a time series
ml-forecast 4 params body → 200
DELETE
/_ml/anomaly_detectors/{job_id}/_forecast
Delete forecasts from a job
ml-delete-forecast 3 params → 200
DELETE
/_ml/anomaly_detectors/{job_id}/_forecast/{forecast_id}
Delete forecasts from a job
ml-delete-forecast-1 4 params → 200
GET
/_ml/anomaly_detectors/{job_id}
Get anomaly detection jobs configuration info
ml-get-jobs 3 params → 200
PUT
/_ml/anomaly_detectors/{job_id}
Create an anomaly detection job
ml-put-job 5 params body → 200
DELETE
/_ml/anomaly_detectors/{job_id}
Delete an anomaly detection job
ml-delete-job 4 params → 200
GET
/_ml/anomaly_detectors/{job_id}/model_snapshots/{snapshot_id}
Get model snapshots info
ml-get-model-snapshots 8 params body → 200
POST
/_ml/anomaly_detectors/{job_id}/model_snapshots/{snapshot_id}
Get model snapshots info
ml-get-model-snapshots-1 8 params body → 200
DELETE
/_ml/anomaly_detectors/{job_id}/model_snapshots/{snapshot_id}
Delete a model snapshot
ml-delete-model-snapshot 2 params → 200
POST
/_ml/anomaly_detectors/_estimate_model_memory
Estimate job model memory usage
ml-estimate-model-memory body → 200
POST
/_ml/anomaly_detectors/{job_id}/_flushdeprecated
Force buffered data to be processed
ml-flush-job 6 params body → 200
GET
/_ml/anomaly_detectors/{job_id}/results/buckets/{timestamp}
Get anomaly detection job results for buckets
ml-get-buckets 11 params body → 200
POST
/_ml/anomaly_detectors/{job_id}/results/buckets/{timestamp}
Get anomaly detection job results for buckets
ml-get-buckets-1 11 params body → 200
GET
/_ml/anomaly_detectors/{job_id}/results/buckets
Get anomaly detection job results for buckets
ml-get-buckets-2 10 params body → 200
POST
/_ml/anomaly_detectors/{job_id}/results/buckets
Get anomaly detection job results for buckets
ml-get-buckets-3 10 params body → 200
GET
/_ml/calendars/{calendar_id}/events
Get info about events in calendars
ml-get-calendar-events 6 params → 200
POST
/_ml/calendars/{calendar_id}/events
Add scheduled events to the calendar
ml-post-calendar-events 1 param body → 200
GET
/_ml/calendars
Get calendar configuration info
ml-get-calendars 2 params body → 200
POST
/_ml/calendars
Get calendar configuration info
ml-get-calendars-1 2 params body → 200
GET
/_ml/anomaly_detectors/{job_id}/results/categories/{category_id}
Get anomaly detection job results for categories
ml-get-categories 5 params body → 200
POST
/_ml/anomaly_detectors/{job_id}/results/categories/{category_id}
Get anomaly detection job results for categories
ml-get-categories-1 5 params body → 200
GET
/_ml/anomaly_detectors/{job_id}/results/categories
Get anomaly detection job results for categories
ml-get-categories-2 4 params body → 200
POST
/_ml/anomaly_detectors/{job_id}/results/categories
Get anomaly detection job results for categories
ml-get-categories-3 4 params body → 200
GET
/_ml/datafeeds/{datafeed_id}/_stats
Get datafeed stats
ml-get-datafeed-stats 2 params → 200
GET
/_ml/datafeeds/_stats
Get datafeed stats
ml-get-datafeed-stats-1 1 param → 200
GET
/_ml/datafeeds
Get datafeeds configuration info
ml-get-datafeeds-1 2 params → 200
GET
/_ml/filters
Get filters
ml-get-filters 2 params → 200
GET
/_ml/anomaly_detectors/{job_id}/results/influencers
Get anomaly detection job results for influencers
ml-get-influencers 9 params body → 200
POST
/_ml/anomaly_detectors/{job_id}/results/influencers
Get anomaly detection job results for influencers
ml-get-influencers-1 9 params body → 200
GET
/_ml/anomaly_detectors/_stats
Get anomaly detection job stats
ml-get-job-stats 1 param → 200
GET
/_ml/anomaly_detectors/{job_id}/_stats
Get anomaly detection job stats
ml-get-job-stats-1 2 params → 200
GET
/_ml/anomaly_detectors
Get anomaly detection jobs configuration info
ml-get-jobs-1 2 params → 200
GET
/_ml/anomaly_detectors/{job_id}/model_snapshots/{snapshot_id}/_upgrade/_stats
Get anomaly detection job model snapshot upgrade usage info
ml-get-model-snapshot-upgrade-stats 3 params → 200
GET
/_ml/anomaly_detectors/{job_id}/model_snapshots
Get model snapshots info
ml-get-model-snapshots-2 7 params body → 200
POST
/_ml/anomaly_detectors/{job_id}/model_snapshots
Get model snapshots info
ml-get-model-snapshots-3 7 params body → 200
GET
/_ml/anomaly_detectors/{job_id}/results/overall_buckets
Get overall bucket results
ml-get-overall-buckets 8 params body → 200
POST
/_ml/anomaly_detectors/{job_id}/results/overall_buckets
Get overall bucket results
ml-get-overall-buckets-1 8 params body → 200
GET
/_ml/anomaly_detectors/{job_id}/results/records
Get anomaly records for an anomaly detection job
ml-get-records 9 params body → 200
POST
/_ml/anomaly_detectors/{job_id}/results/records
Get anomaly records for an anomaly detection job
ml-get-records-1 9 params body → 200
POST
/_ml/anomaly_detectors/{job_id}/_open
Open anomaly detection jobs
ml-open-job 2 params body → 200
POST
/_ml/anomaly_detectors/{job_id}/_datadeprecated
Send data to an anomaly detection job for analysis
ml-post-data 3 params body → 200
GET
/_ml/datafeeds/{datafeed_id}/_preview
Preview a datafeed
ml-preview-datafeed 3 params body → 200
POST
/_ml/datafeeds/{datafeed_id}/_preview
Preview a datafeed
ml-preview-datafeed-1 3 params body → 200
GET
/_ml/datafeeds/_preview
Preview a datafeed
ml-preview-datafeed-2 2 params body → 200
POST
/_ml/datafeeds/_preview
Preview a datafeed
ml-preview-datafeed-3 2 params body → 200
POST
/_ml/anomaly_detectors/{job_id}/_reset
Reset an anomaly detection job
ml-reset-job 3 params → 200
POST
/_ml/anomaly_detectors/{job_id}/model_snapshots/{snapshot_id}/_revert
Revert to a snapshot
ml-revert-model-snapshot 3 params body → 200
POST
/_ml/datafeeds/{datafeed_id}/_start
Start datafeeds
ml-start-datafeed 4 params body → 200
POST
/_ml/datafeeds/{datafeed_id}/_stop
Stop datafeeds
ml-stop-datafeed 5 params body → 200
POST
/_ml/datafeeds/{datafeed_id}/_update
Update a datafeed
ml-update-datafeed 5 params body → 200
POST
/_ml/filters/{filter_id}/_update
Update a filter
ml-update-filter 1 param body → 200
POST
/_ml/anomaly_detectors/{job_id}/_update
Update an anomaly detection job
ml-update-job 1 param body → 200
POST
/_ml/anomaly_detectors/{job_id}/model_snapshots/{snapshot_id}/_update
Update a snapshot
ml-update-model-snapshot 2 params body → 200
POST
/_ml/anomaly_detectors/{job_id}/model_snapshots/{snapshot_id}/_upgrade
Upgrade a snapshot
ml-upgrade-job-snapshot 4 params → 200

Schemas 624

The contract defines 624 schemas that model the data the API accepts and returns. The most detailed are _types.query_dsl.QueryContainer (61 properties), _global.search._types.SearchRequestBody (34 properties), ml._types.Anomaly (24 properties), ml._types.Job (23 properties). Each schema is shown below with its type and property counts.

_types.query_dsl.SpanContainingQuery
_types.query_dsl.TypeQuery
_types.analysis.MinHashTokenFilter
_types.aggregations.TopHitsAggregation
_types.query_dsl.CombinedFieldsZeroTerms
string
_types.aggregations.BucketSelectorAggregation
_types.analysis.HunspellTokenFilter
_types.aggregations.TermsPartition
object
2 properties 2 required
_types.query_dsl.GeoBoundingBoxQuery
_types.SortResults
array
_types.aggregations.BucketCorrelationFunctionCountCorrelationIndicator
object
3 properties 2 required
_types.aggregations.ChildrenAggregation
_types.EpochTimeUnitMillis
_types.aggregations.MatrixAggregation
ml._types.BucketSummary
object
11 properties 10 required
ml._types.MemoryStatus
string
_types.query_dsl.DisMaxQuery
_types.aggregations.SamplerAggregationExecutionHint
string
_types.aggregations.MovingPercentilesAggregation
_types.aggregations.HoltWintersModelSettings
object
6 properties
_types.aggregations.HistogramAggregation
_types.GeoTilePrecision
number
_types.analysis.CompoundWordTokenFilterBase
_types.aggregations.DateRangeAggregation
_types.aggregations.StringStatsAggregation
_types.aggregations.TTestType
string
_types.TextSimilarityReranker
_types.aggregations.ParentAggregation
_types.aggregations.MaxBucketAggregation
_global.search._types.FieldCollapse
object
4 properties 1 required
_types.DateTime
A date and time, either as a string whose format can depend on the context (defaulting to ISO 8601), or a number of milliseconds since the Epoch. Elasticsearch…
_types.query_dsl.RangeQueryBase
_types.query_dsl.NumericDecayFunction
_types.analysis.StemmerOverrideTokenFilter
_types.aggregations.FormattableMetricAggregation
_types.analysis.TokenizerDefinition
_types.query_dsl.UntypedRangeQuery
_types.IndexName
string
_types.aggregations.GeoLineSort
object
1 property 1 required
ml._types.ApiKeyAuthorization
object
2 properties 2 required
_types.analysis.KuromojiPartOfSpeechTokenFilter
ml._types.CalendarEvent
object
8 properties 3 required
_types.aggregations.MultiTermLookup
_types.query_dsl.DecayFunctionBaseGeoLocationDistance
object
1 property
_types.aggregations.CompositeAggregation
_types.analysis.HyphenationDecompounderTokenFilter
_types.query_dsl.SemanticQuery
_types.aggregations.InferenceAggregation
_types.aggregations.HoltWintersMovingAverageAggregation
_types.query_dsl.TextQueryType
string
_types.analysis.KuromojiIterationMarkCharFilter
_types.analysis.StopWords
Language value, such as arabic or thai. Defaults to english. Each language value corresponds to a predefined list of stop words in Lucene. See Stop words by la…
ml._types.ModelSizeStats
object
22 properties 16 required
_types.analysis.SimplePatternSplitTokenizer
_types.aggregations.ScriptedMetricAggregation
_types.analysis.ScandinavianNormalizationTokenFilter
_types.aggregations.StatsBucketAggregation
_types.query_dsl.RangeQueryBaselong
ml._types.DatafeedAuthorization
object
3 properties
ml._types.AnomalyCause
object
15 properties 1 required
_types.analysis.DictionaryDecompounderTokenFilter
_types.analysis.UppercaseTokenFilter
_types.aggregations.BucketPathAggregation
_types.analysis.DelimitedPayloadEncoding
string
_types.aggregations.AggregationRange
object
3 properties
_types.DateFormat
string
ml._types.DatafeedTimingStats
object
7 properties 5 required
_types.DiversifyRetriever
_types.query_dsl.TextExpansionQuery
_types.analysis.ClassicTokenFilter
_types.analysis.SimplePatternTokenizer
_types.analysis.MultiplexerTokenFilter
_types.aggregations.ExtendedStatsBucketAggregation
ml._types.Datafeed
object
16 properties 5 required
_types.analysis.TrimTokenFilter
_types.analysis.PersianNormalizationTokenFilter
_types.analysis.IndicNormalizationTokenFilter
_types.GeoHash
string
_types.query_dsl.WildcardQuery
_global.search._types.HighlighterOrder
string
_types.query_dsl.FuzzyQuery
_types.UnitFloatMillis
number
Time unit for fractional milliseconds
ml._types.ExponentialAverageCalculationContext
object
3 properties 1 required
_types.Id
string
_types.InnerRetriever
object
3 properties 3 required
_types.query_dsl.SparseVectorQuery
_types.analysis.PhoneticNameType
string
_types.SlicedScroll
object
3 properties 2 required
_types.aggregations.SignificantTextAggregation
_types.aggregations.SignificantTermsAggregation
ml._types.JobState
string
ml._types.ModelSnapshot
object
10 properties 6 required
_types.query_dsl.DistanceFeatureQueryBaseGeoLocationDistance
_types.query_dsl.MultiValueMode
string
_types.aggregations.GoogleNormalizedDistanceHeuristic
object
1 property
_types.Sort
_types.query_dsl.TermsSetQuery
ml._types.DelayedDataCheckConfig
object
2 properties 1 required
_types.aggregations.TermsAggregation
_types.analysis.IcuNormalizationMode
string
_types.analysis.IcuCollationAlternate
string
_types.query_dsl.ConstantScoreQuery
ml._types.CategorizationAnalyzerDefinition
object
3 properties
_types.query_dsl.DateRangeQuery
_types.Indices
_types.query_dsl.MatchPhraseQuery
_types.query_dsl.FunctionBoostMode
string
_types.query_dsl.DateDecayFunction
_types.query_dsl.DecayFunctionBasedoubledouble
object
1 property
_types.analysis.TokenChar
string
ml._types.Anomaly
object
24 properties 9 required
_types.query_dsl.HasParentQuery
_types.query_dsl.SpanMultiTermQuery
_types.SortOrder
string
_types.analysis.MappingCharFilter
_types.analysis.CharFilterBase
object
1 property
_types.query_dsl.RankFeatureQuery
ml._types.ExcludeFrequent
string
_types.aggregations.HoltMovingAverageAggregation
_types.analysis.DelimitedPayloadTokenFilter
_types.analysis.SynonymTokenFilter
_types.query_dsl.SpanFirstQuery
ml._types.OverallBucket
object
7 properties 6 required
_types.analysis.DutchStemTokenFilter
_types.query_dsl.MatchBoolPrefixQuery
_types.RuleRetriever
_types.analysis.StopWordLanguage
string
_types.query_dsl.FieldValueFactorModifier
string
_types.GeoHashPrecision
A precision that can be expressed as a geohash length between 1 and 12, or a distance measure like "1km", "10m".
ml._types.JobTimingStats
object
8 properties 4 required
_types.analysis.FingerprintTokenFilter
_types.analysis.LetterTokenizer
_types.Fields
_types.ulong
number
_types.analysis.IcuTransformDirection
string
_spec_utils.Stringifiedboolean
Some APIs will return values such as numbers also as a string (notably epoch timestamps). This behavior is used to capture this behavior while keeping the sema…
_types.query_dsl.SpanNearQuery
_types.aggregations.PercentageScoreHeuristic
object
_global.search._types.ScoreMode
string
_types.analysis.StopTokenFilter
_types.analysis.ThaiTokenizer
_types.query_dsl.IntervalsFuzzy
object
6 properties 1 required
_types.aggregations.MutualInformationHeuristic
object
2 properties
_types.analysis.HtmlStripCharFilter
_types.analysis.IcuFoldingTokenFilter
_types.aggregations.GeoLineAggregation
object
5 properties 1 required
_types.analysis.PatternReplaceCharFilter
_types.PinnedRetriever
_types.RRFRetrieverComponent
object
Wraps a retriever with an optional weight for RRF scoring.
2 properties 1 required
_types.IndicesOptions
object
Controls how to deal with unavailable concrete indices (closed or missing), how wildcard expressions are expanded to actual indices (all, closed or open indice…
4 properties
_types.analysis.PhoneticEncoder
string
_types.ScriptField
object
2 properties 1 required
_types.analysis.SoraniNormalizationTokenFilter
_types.aggregations.EwmaMovingAverageAggregation
_types.query_dsl.CombinedFieldsOperator
string
_types.aggregations.AutoDateHistogramAggregation
_types.aggregations.PercentileRanksAggregation
_types.query_dsl.Operator
string
_types.query_dsl.RuleQuery
ml._types.ClassificationInferenceOptions
object
5 properties
_types.query_dsl.RankFeatureFunctionLinear
_types.RrfRank
_types.aggregations.PipelineAggregationBase
ml._types.Job
object
23 properties 6 required
_types.KnnSearch
object
12 properties 1 required
_types.query_dsl.FunctionScoreQuery
_types.analysis.ApostropheTokenFilter
ml._types.OverallBucketJob
object
2 properties 2 required
_types.mapping.CompositeSubField
object
1 property 1 required
_types.query_dsl.GeoShapeQuery
ml._types.AnalysisConfig
object
11 properties 1 required
_types.analysis.SynonymGraphTokenFilter
_types.UnitSeconds
number
Time unit for seconds
_types.aggregations.MovingFunctionAggregation
_types.TaskId
string
_types.query_dsl.FieldAndFormat
object
A reference to a field with formatting instructions on how to return the value
3 properties 1 required
_types.GeoHexCell
string
A map hex cell (H3) reference
_types.aggregations.TopMetricsAggregation
_types.analysis.PatternCaptureTokenFilter
_types.GeoHashLocation
object
1 property 1 required
_types.analysis.WordDelimiterTokenFilter
ml._types.DiscoveryNode
object
_types.SortOptions
object
4 properties
_types.aggregations.BoxplotAggregation
ml._types.CategorizationAnalyzer
_types.analysis.PredicateTokenFilter
_types.ByteSize
_types.query_dsl.TermsQuery
_global.search._types.BoundaryScanner
string
_types.ScoreNormalizer
string
_types.analysis.IcuNormalizationCharFilter
ml._types.DiscoveryNodeCompact
object
Alternative representation of DiscoveryNode used in ml.getjobstats and ml.getdatafeedstats
5 properties 5 required
_types.aggregations.GeohexGridAggregation
_types.DurationValueUnitFloatMillis
ml._types.RunningStateSearchInterval
object
4 properties 2 required
_types.Field
string
Path to field or array of paths. Some API's support wildcards in the path to select multiple fields.
_types.analysis.NGramTokenFilter
_types.query_dsl.RankFeatureFunctionSaturation
_types.aggregations.StatsAggregation
_types.analysis.ElisionTokenFilter
_types.GeoDistanceSort
object
6 properties
_types.DateMath
string
_types.analysis.KeywordMarkerTokenFilter
_types.mapping.RuntimeFields
object
_types.TimeZone
string
_types.analysis.KeywordTokenizer
_types.query_dsl.MatchPhrasePrefixQuery
_types.analysis.KeepTypesMode
string
_types.aggregations.CartesianCentroidAggregation
_types.Embedding
object
3 properties 1 required
_types.analysis.TokenFilter
_types.analysis.EdgeNGramTokenizer
_types.query_dsl.SpanTermQuery
_types.CoordsGeoBounds
object
4 properties 4 required
_types.query_dsl.MultiMatchQuery
_types.analysis.BrazilianStemTokenFilter
_types.InferenceStringGroup
_types.query_dsl.GeoExecution
string
_types.aggregations.MetricAggregationBase
object
3 properties
_types.ExpandWildcard
string
_types.query_dsl.UntypedDistanceFeatureQuery
_types.Script
object
5 properties
_types.analysis.AsciiFoldingTokenFilter
_types.query_dsl.ChildScoreMode
string
_types.GeoLocation
A latitude/longitude as a 2 dimensional point. It can be represented in various ways: - as a {lat, long} object - as a geo hash value - as a [lon, lat] array -…
_types.aggregations.CompositeAggregationBase
object
6 properties
_types.analysis.PersianStemTokenFilter
_types.aggregations.MatrixStatsAggregation
_types.aggregations.TTestAggregation
_types.aggregations.ScriptedHeuristic
object
1 property 1 required
_types.mapping.RuntimeFieldFetchFields
object
2 properties 1 required
_types.aggregations.FrequentItemSetsAggregation
object
5 properties 1 required
_types.aggregations.FiltersAggregation
_types.query_dsl.IntervalsAnyOf
object
2 properties 1 required
_types.aggregations.PValueHeuristic
object
2 properties
_types.analysis.DecimalDigitTokenFilter
_types.aggregations.BucketCorrelationAggregation
A sibling pipeline aggregation which executes a correlation function on the configured sibling multi-bucket aggregation.
_types.GeoTile
string
A map tile reference, represented as {zoom}/{x}/{y}
_types.analysis.TokenFilterDefinition
_global.search._types.HighlighterType
_types.WktGeoBounds
object
1 property 1 required
_types.aggregations.ChangePointAggregation
_types.mapping.RuntimeFieldType
string
_types.query_dsl.CombinedFieldsQuery
_types.TextEmbedding
object
2 properties 1 required
_types.NodeId
string
_types.analysis.KuromojiReadingFormTokenFilter
ml._types.JobStatistics
object
4 properties 4 required
_types.RescorerRetriever
_types.query_dsl.DistanceFeatureQuery
ml._types.RuleAction
string
_types.analysis.ConditionTokenFilter
ml._types.AnalysisLimits
object
2 properties
_types.aggregations.CartesianBoundsAggregation
_types.GeoBounds
A geo bounding box. It can be represented in various ways: - as 4 top/bottom/left/right coordinates - as 2 topleft / bottomright points - as 2 topright / botto…
_global.search._types.SearchRequestBody
object
34 properties
_types.analysis.IcuCollationTokenFilter
_types.TopLeftBottomRightGeoBounds
object
2 properties 2 required
_types.query_dsl.IntervalsQuery
_types.NestedSortValue
object
4 properties 1 required
_types.query_dsl.RankFeatureFunction
object
_global.search._types.SourceFilter
object
3 properties
_types.QueryVectorBuilder
object
3 properties
ml._types.Influencer
object
11 properties 10 required
_types.query_dsl.SpanNotQuery
_types.analysis.NoriTokenizer
_types.analysis.IcuNormalizationType
string
_types.aggregations.MovingAverageAggregationBase
_types.Ids
_types.query_dsl.RegexpQuery
_types.aggregations.FieldDateMath
A date range limit, represented either as a DateMath expression or a number expressed according to the target field's precision.
_types.DiversifyRetrieverTypes
string
_types.Metadata
object
ml._types.DetectionRule
object
3 properties
_types.aggregations.AverageAggregation
_types.GeoDistanceType
string
_types.TokenPruningConfig
object
3 properties
_types.TopRightBottomLeftGeoBounds
object
2 properties 2 required
ml._types.Influence
object
2 properties 2 required
_types.query_dsl.QueryBase
object
2 properties
_types.analysis.PhoneticLanguage
string
_types.query_dsl.PercolateQuery
_types.query_dsl.IntervalsWildcard
object
3 properties 1 required
_types.aggregations.TermsExclude
_types.query_dsl.WrapperQuery
_types.query_dsl.FieldValueFactorScoreFunction
object
4 properties 1 required
_types.analysis.PatternTokenizer
_types.aggregations.TermsAggregationExecutionHint
string
_types.analysis.NoriPartOfSpeechTokenFilter
ml._types.DetectorRead
object
10 properties 1 required
_types.analysis.TokenizerBase
object
1 property
_types.aggregations.SerialDifferencingAggregation
_types.query_dsl.QueryContainer
object
An Elasticsearch Query DSL (Domain Specific Language) object that defines a query.
61 properties
_types.analysis.HindiNormalizationTokenFilter
_types.aggregations.MinimumInterval
string
ml._types.Detector
object
10 properties
_types.ScoreSort
object
1 property
_types.aggregations.BucketSortAggregation
_types.query_dsl.CommonTermsQuery
_spec_utils.PipeSeparatedFlagsSimpleQueryStringFlag
A set of flags that can be represented as a single enum value or a set of values that are encoded as a pipe-separated string Depending on the target language,…
_types.KnnQuery
_types.Fuzziness
_types.analysis.JaStopTokenFilter
_types.EmptyObject
object
For empty Class assignments
_types.SortMode
string
_types.query_dsl.PinnedDoc
object
2 properties 1 required
_types.analysis.ArabicStemTokenFilter
_global.search._types.Rescore
_types.QueryVector
array
_types.aggregations.BucketsQueryContainer
Aggregation buckets. By default they are returned as an array, but if the aggregation has keys configured for the different buckets, the result is a dictionary.
_types.query_dsl.DistanceFeatureQueryBase
_types.Name
string
_types.aggregations.SumBucketAggregation
_types.aggregations.Missing
_types.aggregations.DateHistogramAggregation
_types.query_dsl.RangeQueryBasedouble
_types.query_dsl.IdsQuery
_types.query_dsl.BoostingQuery
_global.search._types.HighlighterEncoder
string
_types.query_dsl.QueryStringQuery
_types.query_dsl.SpanWithinQuery
_types.MultiTermQueryRewrite
string
_types.analysis.RussianStemTokenFilter
_types.aggregations.WeightedAverageValue
object
3 properties
_types.query_dsl.IntervalsRegexp
object
3 properties 1 required
_types.analysis.KeywordRepeatTokenFilter
_types.query_dsl.DecayFunctionBaseDateMathDuration
object
1 property
_types.TransportAddress
string
_types.analysis.WhitespaceTokenizer
_global.search._types.InnerHits
object
17 properties
_types.query_dsl.SpanQuery
object
10 properties
_types.aggregations.TDigestExecutionHint
string
_global.search._types.RescoreQuery
object
4 properties 1 required
_types.aggregations.MissingOrder
string
_types.ExpandWildcards
_types.ScriptLanguage
ml._types.JobBlockedReason
string
_types.query_dsl.SpanGapQuery
object
Can only be used as a clause in a spannear query.
_types.analysis.WordDelimiterTokenFilterBase
_types.query_dsl.ExistsQuery
_types.RankBase
object
_types.analysis.SynonymFormat
string
_types.RetrieverContainer
object
9 properties
_types.VersionString
string
_types.query_dsl.ParentIdQuery
ml._types.DatafeedStats
object
6 properties 2 required
_types.analysis.FrenchStemTokenFilter
_types.analysis.KeepTypesTokenFilter
_types.RelationName
string
_types.query_dsl.GeoPolygonQuery
_types.query_dsl.MatchAllQuery
_types.KnnRetriever
_types.mapping.ChunkRescorerChunkingSettings
object
6 properties 1 required
_types.aggregations.IpPrefixAggregation
_types.analysis.IcuCollationCaseFirst
string
_types.analysis.SnowballTokenFilter
_types.aggregations.MissingAggregation
_types.aggregations.MaxAggregation
_types.analysis.PhoneticRuleType
string
_types.analysis.UniqueTokenFilter
_types.aggregations.BucketKsAggregation
A sibling pipeline aggregation which executes a two sample Kolmogorov–Smirnov test (referred to as a "K-S test" from now on) against a provided distribution, a…
_types.KnnEmbeddingInput
Knn embedding input. Either a string, an object or array of objects
ml._types.SnapshotUpgradeState
string
_types.RRFRetriever
_types.InferenceString
object
3 properties 2 required
_global.search._types.HighlightField
_types.aggregations.SumAggregation
_types.aggregations.ExtendedStatsAggregation
_types.analysis.SynonymTokenFilterBase
_types.analysis.KuromojiStemmerTokenFilter
_global.search._types.LearningToRank
object
2 properties 1 required
ml._types.JobForecastStatistics
object
6 properties 2 required
_types.ScriptSortType
string
_types.query_dsl.IntervalsContainer
object
8 properties
ml._types.RegressionInferenceOptions
object
2 properties
_types.mapping.RuntimeField
object
9 properties 1 required
ml._types.AnomalyExplanation
object
10 properties
_types.query_dsl.RandomScoreFunction
object
2 properties
_types.aggregations.MedianAbsoluteDeviationAggregation
_types.query_dsl.LikeDocument
object
8 properties
_types.aggregations.RangeAggregation
_types.analysis.IcuCollationStrength
string
_types.analysis.GermanStemTokenFilter
_types.analysis.CharFilter
_types.analysis.TruncateTokenFilter
_types.analysis.LimitTokenCountTokenFilter
ml._types.JobConfig
object
16 properties 2 required
_types.aggregations.SamplerAggregation
_types.query_dsl.PinnedQuery
_global.search._types.HighlighterTagsSchema
string
ml._types.Category
object
14 properties 8 required
ml._types.CategorizationStatus
string
_types.aggregations.IpRangeAggregationRange
object
3 properties
_types.ScriptSort
object
5 properties 1 required
_types.query_dsl.FunctionScoreContainer
ml._types.ChunkingConfig
object
2 properties 1 required
_types.aggregations.HoltWintersType
string
_types.analysis.IcuTokenizer
inference._types.EmbeddingContentFormat
string
ml._types.FilterType
string
ml._types.BucketInfluencer
object
11 properties 10 required
_types.analysis.WordDelimiterGraphTokenFilter
_types.query_dsl.IntervalsAllOf
object
4 properties 1 required
_types.aggregations.RandomSamplerAggregation
_types.query_dsl.ShapeQuery
ml._types.AppliesTo
string
_types.aggregations.NormalizeAggregation
_types.analysis.CharFilterDefinition
_types.analysis.CjkBigramTokenFilter
_types.aggregations.MovingAverageAggregation
_types.query_dsl.SimpleQueryStringFlags
Query flags can be either a single flag or a combination of flags, e.g. OR|AND|PREFIX
_types.aggregations.CompositeDateHistogramAggregation
_types.analysis.CharGroupTokenizer
_types.aggregations.CardinalityAggregation
_types.query_dsl.RangeRelation
string
ml._types.DetectorUpdate
object
3 properties 1 required
_types.analysis.KuromojiTokenizer
_types.analysis.NGramTokenizer
_types.analysis.KuromojiTokenizationMode
string
_types.analysis.StemmerTokenFilter
_types.analysis.CommonGramsTokenFilter
_types.query_dsl.DecayFunction
_types.query_dsl.PrefixQuery
_types.analysis.IcuCollationDecomposition
string
_global.search._types.SourceConfig
Defines how to fetch a source. Fetching can be disabled entirely, or the source can be filtered.
_global.search._types.HighlightBase
object
21 properties
_types.DurationLarge
string
A date histogram interval. Similar to Duration with additional units: w (week), M (month), q (quarter) and y (year)
_types.LatLonGeoLocation
object
2 properties 2 required
_types.analysis.UaxEmailUrlTokenizer
_types.aggregations.NormalizeMethod
string
_types.aggregations.PercentilesAggregation
_types.analysis.IcuNormalizationTokenFilter
_types.aggregations.VariableWidthHistogramAggregation
object
5 properties
_types.aggregations.RateAggregation
_types.aggregations.CategorizeTextAggregation
A multi-bucket aggregation that groups semi-structured text into buckets. Each text field is re-analyzed using a custom analyzer. The resulting tokens are then…
_types.query_dsl.IntervalsFilter
object
9 properties
_types.aggregations.TestPopulation
object
3 properties 1 required
_types.aggregations.CustomCategorizeTextAnalyzer
object
3 properties
_types.aggregations.MultiTermsAggregation
ml._types.RuleCondition
object
3 properties 3 required
_global.search._types.Highlight
_types.query_dsl.SpanFieldMaskingQuery
_types.analysis.ShingleTokenFilter
_types.aggregations.GeoLinePoint
object
1 property 1 required
_types.aggregations.AdjacencyMatrixAggregation
_types.query_dsl.ScriptQuery
ml._types.Filter
object
3 properties 2 required
_types.query_dsl.RangeQueryBaseDateMath
ml._types.CustomSettings
object
Custom metadata about the job
_types.query_dsl.RangeQuery
_types.Distance
string
_types.aggregations.TopMetricsValue
object
1 property 1 required
_types.aggregations.CumulativeSumAggregation
_types.DurationValueUnitMillis
_types.aggregations.GeoTileGridAggregation
_types.analysis.TokenFilterBase
object
1 property
_types.query_dsl.DecayFunctionBase
object
1 property
_types.query_dsl.GeoDistanceFeatureQuery
_types.analysis.ArabicNormalizationTokenFilter
_global.search._types.HighlighterFragmenter
string
_types.FieldValue
A field value.
_types.RankContainer
object
1 property
_types.query_dsl.IntervalsPrefix
object
3 properties 1 required
_types.aggregations.BucketAggregationBase
Base type for bucket aggregations. These aggregations also accept sub-aggregations.
_types.aggregations.ChiSquareHeuristic
object
2 properties 2 required
_global.search._types.PointInTimeReference
object
2 properties 1 required
_types.analysis.LowercaseTokenizer
_types.query_dsl.MoreLikeThisQuery
ml.get_calendars.Calendar
object
3 properties 2 required
_types.aggregations.CompositeTermsAggregation
_types.query_dsl.RankFeatureFunctionSigmoid
_types.RescoreVector
object
1 property 1 required
_types.aggregations.TermsAggregationCollectMode
string
_types.analysis.NoriDecompoundMode
string
_types.aggregations.WeightedAverageAggregation
_types.AcknowledgedResponseBase
object
1 property 1 required
_types.analysis.SnowballLanguage
string
_types.query_dsl.Like
Text that we want similar documents for or a lookup to a document's field for the text.
_types.aggregations.AggregationContainer
_types.RRFRetrieverEntry
Either a direct RetrieverContainer (backward compatible) or an RRFRetrieverComponent with weight.
_types.MinimumShouldMatch
The minimum number of terms that should match as integer, percentage or range
_types.HttpHeaders
object
_types.aggregations.FrequentItemSetsField
object
3 properties 1 required
_types.aggregations.CategorizeTextAnalyzer
_types.query_dsl.ScriptScoreQuery
_types.aggregations.ReverseNestedAggregation
_types.analysis.Tokenizer
_types.aggregations.GeoHashGridAggregation
_types.query_dsl.NestedQuery
_types.query_dsl.TermQuery
_types.analysis.StandardTokenizer
_types.aggregations.EwmaModelSettings
object
1 property
_types.DurationValueUnitSeconds
_types.aggregations.FormatMetricAggregationBase
_types.aggregations.ExtendedBoundsFieldDateMath
object
2 properties
_types.query_dsl.GeoGridQuery
_types.DistanceUnit
string
_types.query_dsl.NumberRangeQuery
_types.aggregations.AverageBucketAggregation
_types.aggregations.CardinalityExecutionMode
string
_types.aggregations.RateMode
string
_types.aggregations.CompositeGeoTileGridAggregation
_types.analysis.BengaliNormalizationTokenFilter
_types.aggregations.DerivativeAggregation
_types.aggregations.CompositeHistogramAggregation
_types.aggregations.HdrMethod
object
1 property
_types.analysis.CjkWidthTokenFilter
_types.VersionNumber
number
_global.search._types.TrackHits
Number of hits matching the query to count accurately. If true, the exact number of hits is returned at the cost of some performance. If false, the response do…
_types.query_dsl.FunctionScoreMode
string
_types.analysis.ReverseTokenFilter
ml._types.JobStats
object
10 properties 6 required
_types.query_dsl.GeoValidationMethod
string
ml._types.PerPartitionCategorization
object
2 properties
_types.aggregations.BucketCorrelationFunctionCountCorrelation
object
1 property 1 required
_types.query_dsl.LongNumberRangeQuery
_types.analysis.ClassicTokenizer
_types.Duration
A duration. Units can be nanos, micros, ms (milliseconds), s (seconds), m (minutes), h (hours) and d (days). Also accepts "0" without a unit and "-1" to indica…
_spec_utils.Stringifiedinteger
Some APIs will return values such as numbers also as a string (notably epoch timestamps). This behavior is used to capture this behavior while keeping the sema…
_types.query_dsl.DistanceFeatureQueryBaseDateMathDuration
_types.query_dsl.TermRangeQuery
_types.aggregations.DateRangeExpression
object
3 properties
_types.aggregations.ValueType
string
_global.search._types.Suggester
object
1 property
_types.aggregations.GeoBoundsAggregation
_types.analysis.SerbianNormalizationTokenFilter
_types.LinearRetriever
_types.analysis.CzechStemTokenFilter
_types.analysis.LowercaseTokenFilterLanguages
string
_types.LookupQueryVectorBuilder
object
4 properties 3 required
_types.query_dsl.MatchNoneQuery
_types.query_dsl.UntypedDecayFunction
_types.aggregations.SimpleMovingAverageAggregation
ml._types.JobBlocked
object
2 properties 1 required
ml._types.DatafeedState
string
_types.mapping.OnScriptError
string
_types.query_dsl.ZeroTermsQuery
string
_types.RetrieverBase
object
3 properties
ml._types.DataCounts
object
19 properties 12 required
ml._types.DataDescription
object
4 properties
_types.aggregations.TDigest
object
2 properties
_types.analysis.GermanNormalizationTokenFilter
_types.VersionType
string
_types.aggregations.RareTermsAggregation
_types.aggregations.GeoDistanceAggregation
_types.aggregations.ExtendedBoundsdouble
object
2 properties
_types.StandardRetriever
ml._types.DatafeedConfig
object
14 properties
_types.aggregations.BucketScriptAggregation
ml._types.ModelPlotConfig
object
3 properties
_types.aggregations.TermsInclude
_types.aggregations.LinearMovingAverageAggregation
_types.aggregations.ValueCountAggregation
ml._types.ModelSnapshotUpgrade
object
5 properties 5 required
ml._types.FilterRef
object
2 properties 1 required
_types.analysis.EdgeNGramSide
string
_types.query_dsl.HasChildQuery
_types.analysis.ScandinavianFoldingTokenFilter
_types.query_dsl.DateDistanceFeatureQuery
_types.aggregations.GlobalAggregation
ml._types.AnalysisMemoryLimit
object
1 property 1 required
_types.aggregations.Aggregation
object
_types.analysis.LowercaseTokenFilter
_types.query_dsl.SpanOrQuery
_types.aggregations.TimeSeriesAggregation
_types.query_dsl.BoolQuery
_types.SpecifiedDocument
object
2 properties 1 required
_types.query_dsl.SimpleQueryStringQuery
_types.aggregations.InferenceConfigContainer
object
2 properties
_types.SortCombinations
_types.aggregations.GapPolicy
string
_types.analysis.FlattenGraphTokenFilter
_types.analysis.LengthTokenFilter
_types.analysis.PatternReplaceTokenFilter
ml._types.ChunkingMode
string
ml._types.AnalysisConfigRead
object
11 properties 3 required
_types.query_dsl.RangeQueryBasestring
_types.query_dsl.ScriptScoreFunction
object
1 property 1 required
_types.aggregations.DiversifiedSamplerAggregation
_types.aggregations.NestedAggregation
_types.analysis.CjkBigramIgnoredScript
string
_types.aggregations.CalendarInterval
string
_types.ScriptSource
_types.analysis.KeepWordsTokenFilter
_types.aggregations.CompositeAggregateKey
object
ml._types.DatafeedRunningState
object
3 properties 2 required
_types.analysis.RemoveDuplicatesTokenFilter
_types.query_dsl.MatchQuery
_types.aggregations.CumulativeCardinalityAggregation
_types.analysis.EdgeNGramTokenFilter
_types.query_dsl.SimpleQueryStringFlag
string
_types.query_dsl.WeightedTokensQuery
_types.Routing
Only to be used in query and path parameters, as the array form is actually a csv
_types.aggregations.BucketsPath
Buckets path can be expressed in different ways, and an aggregation may accept some or all of these forms depending on its type. Please refer to each aggregati…
_types.aggregations.MinBucketAggregation
_types.aggregations.GeoCentroidAggregation
ml._types.Page
object
2 properties
_types.query_dsl.IntervalsRange
object
6 properties
ml._types.ConditionOperator
string
_types.analysis.PathHierarchyTokenizer
_global.search._types.ScriptRescore
object
1 property 1 required
_types.query_dsl.RankFeatureFunctionLogarithm
_types.query_dsl.GeoDistanceQuery
_types.query_dsl.GeoDecayFunction
_types.aggregations.BucketCorrelationFunction
object
1 property 1 required
_types.analysis.PorterStemTokenFilter
_types.analysis.IcuTransformTokenFilter
_types.analysis.PhoneticTokenFilter
_types.query_dsl.IntervalsMatch
object
6 properties 1 required
_types.NodeIds
_types.aggregations.PercentilesBucketAggregation
_types.ChunkRescorer
object
2 properties
inference._types.EmbeddingContentType
string
_types.aggregations.IpRangeAggregation
_types.analysis.KStemTokenFilter
_types.aggregations.AggregateOrder
ml._types.GeoResults
object
2 properties
ml._types.DiscoveryNodeContent
object
9 properties 8 required
_types.aggregations.MinAggregation
_types.aggregations.CompositeAggregationSource
object
4 properties
_types.aggregations.HoltLinearModelSettings
object
2 properties
_types.GrokPattern
string
_types.CategoryId
number
_types.UnitMillis
number
Time unit for milliseconds

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

elk-stack-ml-anomaly-api-openapi.yml Raw ↑

Other APIs Elastic Stack (ELK Stack) publishes across the network.

Elastic Cloud API
Elastic Stack (ELK Stack) Accounts API
Elastic Stack (ELK Stack) Actions API
Elastic Stack (ELK Stack) agent builder API
Elastic Stack (ELK Stack) Alerting API
Elastic Stack (ELK Stack) Alerting V2 API
Elastic Stack (ELK Stack) Analytics API
Elastic Stack (ELK Stack) APM agent configuration API
Elastic Stack (ELK Stack) APM agent keys API
Elastic Stack (ELK Stack) APM annotations API
Elastic Stack (ELK Stack) APM server schema API
Elastic Stack (ELK Stack) APM sourcemaps API
Where this information came from

This is an independent, third-party profile of Elastic Stack (ELK Stack) ml anomaly API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.