epok

Statistical

Outlier Detection

Updated Jul 28, 2026 · 1d ago

Multi-dimensional outliers in log feature space. Catches subtle anomalies that single-axis thresholds miss.

Example alert

api-gateway request cluster outlier: status=200 + latency=12s + body=8MB (1 in 50,000 vs baseline)

Exact wording varies — the detector generates titles from the anomaly it finds. This is representative of what an alert looks like when it fires.

How it works

Builds a multi-dimensional feature profile per service from structured log fields (status codes, latencies, sizes). Isolation forest scoring identifies requests that are rare across multiple dimensions simultaneously. Learning period: 7 days.

Availability

Runs on these tiers:

TrialTeamGrowthCustom

Want to see this detector firing in the live demo?

Open alerts in the sandbox →

Related detectors

  • Volume Anomaly

    Detects spikes, drops, and flatlines in log volume vs daily and weekly baselines per service.

  • Silence Detection

    Catches services that stop logging when they normally log every N seconds. The most dangerous failure mode: no errors, just absence.

  • Numeric Field Anomaly

    Discovers the numeric fields your logs carry — payment amounts, cache hit rates, queue depths, inference scores — and flags when one drifts from its baseline.

  • Post-Change Regression

    Checks whether a deploy, config change or scale event actually made things worse, by comparing the window after the change against the matched window before it — per service.

  • Error Growth Forecast

    Spots an error signature whose arrival rate is climbing and projects when it reaches a volume that matters — as a time range, before the incident, not after.

← All detectors