The usual sequence in investigating an anomaly is as follows:
- You probably received an alert notification. You either click Investigate in the notification or you choose the Triage from the alert console. Working with Triage is described here.
- If you chose to do a 'deep investigation' of the alert, it will open the investigation page.
- The Anomap and chart for the specific anomaly opens together with other metrics that are in the same anomalies group.
- Zoom in on the anomaly spike and the surrounding periods to see if any metrics might indicate the beginning of the problem. You can sort by Start time, Significance or Delta to view the group by the metrics that became anomalous first.
Note: To Zoom in place the cursor to one side of an anomaly spike and while holding the left mouse button down, drag the cursor to the other side of the spike - In the expression box, create an investigative expression using the same method as for building the metric. See Metric Expressions.
- Using a combination of the filters and property/value expressions, eliminate suspected metrics until the root cause is discovered.
- Go to the Anoboard and set the time filter to the time around the start time of the alert, and see if there are other anomalies groups that help isolate the cause of the anomaly in the alert you received.
TO INVESTIGATE AN ANOMALY DIRECTLY FROM THE ANOBOARD PAGE
- Select an Anomalies dashboard.
- Click Investigate in the Anomalies chart that you want to investigate. A new tabbed page is created display the selected Anomaly, or group of Anomalies and their corresponding Anomaps.
Note:
Denotes a Transient anomaly type
Denotes a Pattern Change anomaly type
When investigating an issue, you can open multiple anomalies and easily switch between them by clicking the tabs.
- To change the properties displayed on the Anomap, hover over the property, a Hide property from Anomap button is display. Click it. The property is hidden from all the Anomaps. The next most relevant property is displayed.
Note To display the default Anomap, click RESET ANOMAP. - In the chart, trace the anomaly with the cursor. The date and time of the anomaly, the severity color code, and the severity rating appear at every point along the anomaly chart spike.
- To copy the metric name to the clipboard, hover over the heading with the metric description, a Copy key is display. Click Copy, a message is displayed Copied to Clipboard.
- To re-sort the anomaly charts, open the Sort drop-down menu. Anomaly charts can be sorted by Start date, Significance or Delta.
- Continue investigating metrics until you can determine a root cause, or search other anomalies groups to detect a root cause.