Skip to content

Production MLOps Platform · Jul 2026

realtime-anomaly-detection: Streaming Detection and Alerting

Event to deduplicated alert in under two seconds

Source

The problem

Anomalies in streaming data need catching in near real time, and simulated benchmarks lie.

Approach

Redpanda ingestion with Faust stream processing over rolling 1-minute, 5-minute and 1-hour windows. Three detectors with hot-reload: Isolation Forest, LSTM autoencoder and a Z-score baseline, plus severity scoring, alert deduplication and historical replay for backtesting. Validated against a real Kaggle fraud dataset after simulated data returned implausible results.

How it works

Key decisions

Route by source type instead of picking one detector
Fraud is a multi-feature interaction, server metrics are a deviation from a running baseline, and IoT anomalies are temporal. No single detector handles all three well, so the router chooses per source.
Distrust the simulator
Injected anomalies are cleanly separable — large amount and foreign and odd hour, all at once — so the detectors score near-perfectly on them. Those numbers measure the pipeline, not detection ability, and the README says so before quoting any of them.
Revalidate against real fraud data
Real base rates are often 0.1% or lower, anomalies look almost normal, and there are usually no labels. The simulated result was published as a warning rather than as a result.

Interface

Grafana dashboard showing event volume, open alerts and detection latency
Event volume against anomalies, open alerts by severity, and detection latency, with the most recent detections listed.

What broke

Running it

docker compose up

Full setup, configuration and API reference are in the repository README.

Stack

Written up in