The following methodologies (in the same order specified below) are usually considered for the final score determination:
1. Another attribute of the same monitor detected as anomalous
It facilitates the increase of the overall anomaly score if an anomaly is detected with another attribute of the same monitor.
2. Dependent monitors detected with anomaly
Severity of the anomaly detected in a monitor can be increased if any of the monitors, which are dependent on it or monitor for which it is dependent has anomalies. For example, a URL monitor has a Server monitor as a dependent monitor. If URL monitor has 'Response time' anomaly and at the same time interval, a Server monitor also has 'CPU Usage anomaly', then the score and severity of anomaly will be increased. It can also be inferred that Response time spike is due to spike in CPU usage of underlying server.
These dependent monitors are associated during the additon of the monitor.
3. Parent/child monitors are anomalous
Dependency scoring can also be done using Parent/Child dependency. For example, if an underlying plugin monitor has any anomaly, it will also affect the health of the parent server monitor. So, whenever an anomaly occurs in a monitor, we will check if there exists any child monitor of it. If the child monitor also has anomaly, score will be increased and we can infer that the anomaly in parent might be caused due to child monitor's anomaly.
4. Monitors, grouped under the same Monitor Group detected as anomalous
If any of the monitors in the monitor groups (to which current monitor with anomaly belongs to) have anomalies in last half an hour, then it'll increase the overall score. There are two types to add the score:
Infrastructure monitors:
For infrastructure monitors, if there's an anomaly in the same monitor group, it increases the overall score.
Non-infrastructure monitors:
If non-infrastructure monitors have anomaly in same monitor group, it increases the score.
If monitors with same tags have anomaly, it increases the score for ingrastructure as well as non-infrastructure monitors.
6. Monitors with the same Fully Qualified Domain Name (FQDN) has anomaly
Monitors having same domain name can also be grouped together for Anomaly scoring. In most of the cases, monitors with same domain are affected or have anomalies at the same period.
7. Monitors with the same Server name
Monitors having same server name can be grouped together for Anomaly scoring.
8. Same Monitor Type
If none of the above cases are satisfied, scoring is handled based on anomalies detected in other monitors of the similar monitor type.
Related Articles
How to enable or disable anomaly alerts
Understanding alerts In Site24x7, there are two different types of alerts in anomaly detection: Status change alert: Triggered when there is a change in the monitor status, such as Trouble, Critical, or Down. Anomaly alert: Triggered when irregular ...
Troubleshooting steps for No anomaly triggered
Why are anomaly alerts not triggered? If you are not receiving anomaly alerts, it means that the model was not able to recognize a behavior as an anomaly. Site24x7's AI-powered Zia framework is the underlying mechanism of anomaly detection. The ML ...
How are the average values calculated in Global Benchmark Report and Monitor Group Performance Report?
Response time data in a Monitor Group Performance report and Monitor Group Global Benchmark Report is calculated using different logic. As a result, you may notice a slight deviation in the average values deciphered from these reports. Monitor Group ...
FAQ on custom report
Custom Reports provide the flexibility to create reports that match your specific monitoring and reporting requirements. The following questions cover key aspects of Custom Reports: What are Resource Inventory and Monitoring Inventory attributes? ...
Cisco Meraki Dashboard Access vs API Access Explained
When configuring Cisco Meraki monitors in Site24x7, the API endpoint used determines whether the request is treated as API access or Dashboard access. If the incorrect allowlist is configured, API requests may fail even though authentication details ...