Loss prevention
Use the Loss prevention reports to check for transaction anomalies for the selected time period and to make transaction volume predictions. You can filter the anomalies and predictions on: subtenant, site group, site, and machine.
Note
The Loss prevention feature requires the connect/predictions/anomalies/get permission.
For more information on permissions, see Connect 2 FAQ.
Transaction volume anomalies
The Transaction volume anomalies report is auto-generated when transaction values are outside the boundaries.
This is the information shown in the columns in the Transaction volume anomalies report.
Column | Description |
|---|---|
Identity/Grouping | |
Machine UUID | The unique machine identifier |
Currency | The currency of the transaction. For example, GBP or EUR. |
Transaction type | The kind of transaction being counted. For example, DISPENSE or DEPOSIT. |
Window | The bucket size used for aggregation. These are the options: FIVE_MINUTES, ONE_HOUR, or ONE_DAY. |
Event type | The classification of what was detected as VOLUME_ANOMALY |
Time frame of the measurement | |
Window start | The start timestamp of the bucket being evaluated. |
Window end | The end timestamp of the bucket being evaluated |
Produced at | The time when the anomaly record was generated |
The core comparison | |
Actual value | The real measured value in this window sum for the bucket |
Baseline value | The expected value the actual value is compared against. That is, the model’s prediction for this window |
Lower bound | The bottom of the acceptable range; below this = anomalously low |
Upper bound | The top of the acceptable range; above this = anomalously high |
How far off it was | |
Deviation | The absolute difference between actual and baseline (`actual − baseline`) |
Deviation % | The deviation difference as a percentage of the baseline (relative size of the miss) |
Same-slot median | The median value for the same time slot historically (for example, “this hour-of-day / this day-of-week”), used as a seasonality-aware reference so a Monday-9 a.m. spike is compared to other Mondays at 9 a.m. |
Anomaly flags | |
Above anomaly | The true/flag when actual exceeded the upper bound (unusually high volume) |
Below anomaly | The true/flag when actual fell below the lower bound (unusually low volume) |
Confidence / how much history backed the model | |
History points | The number of historical data points available to build the baseline/bounds. Few points means less reliable. |
Lookback months | How far back the model looked when building the baseline (the training window length) |
Transaction frequency predictions
The Transaction frequency predictions report predicts how frequently transactions are made on a specific machine. This information is useful when determining when the machine needs to be filled up or emptied.
This is the information shown in the columns in the Transaction frequency predictions.
Column | Description |
|---|---|
Machine UUID | The unique machine identifier |
Series ID | The identifier of the specific time series being forecast: tenant + machine_uuid |
Evaluated at | The timestamp the prediction was made |
Predicted transaction count | The model’s forecasted number of transactions for that point, expected estimate |
Predicted lower bound | The bottom of the prediction’s confidence interval; the forecast says the value should be at least this. |
Predicted upper bound | The top of the confidence interval; the value should be at most this. Together, lower and upper give the expected range. |
Observed transaction count | The actual number of transactions that really occurred, for comparison against the prediction. If the actual number falls outside lower–upper, the reality diverged from the forecast. |
History points | How many historical data points fed the model when making the prediction. More points means a more reliable forecast; too few means low confidence. |
See also