Custom action for Anomaly Detection

Hi I’m new to Open Distro and currently utilizing Anomaly Detection with metricbeats index.
The system fields that I’m using is, using features with aggregation for average and max.

The Anomaly Detection works just fine, but I’m wondering if there’s anyway I can figure out the process name that’s causing when the detector detects anomalies.


We don’t start separate process for anomaly detection.