Understanding the advanced detector functions
In addition to the detector functions mentioned so far, there are also a few other, more advanced functions that allow some very unique capabilities. Some of these functions are only available if the ML job is configured via the advanced job wizard or via the API.
rare
In the context of a stream of temporal information (such as a log file), the notion of something being statistically rare (occurring at a low frequency) is paradoxically both intuitive and hard to understand. If I were asked, for example, to trawl through a log file and find a rare message, I might be tempted to label the first novel message that I saw as a rare one. But what if practically every message was novel? Are they all rare? Or is nothing rare?
In order to define rarity to be useful in the context of a stream of events in time, we need to agree that the declaration of something as being rare must take into account the context in which it exists. If there...