{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-292-allow-for-resource-health-transitions-that-never-enter-the-activity-log/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-292-allow-for-resource-health-transitions-that-never-enter-the-activity-log/",
        "slug": "dse-20260909-292-allow-for-resource-health-transitions-that-never-enter-the-activity-log",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-292-allow-for-resource-health-transitions-that-never-enter-the-activity-log/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-292-allow-for-resource-health-transitions-that-never-enter-the-activity-log.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-292-allow-for-resource-health-transitions-that-never-enter-the-activity-log/"
        },
        "title": "Allow for Resource Health transitions that never enter the Activity Log",
        "summary": "Resource Health's documented logging exclusions prevent the Activity Log from being a complete record of every observed state change.",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:27:04+00:00",
        "modified_at": "2026-09-10T01:23:49+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 245,
        "potentially_affected": "Azure Resource Health investigations using Activity Log events, including virtual-machine health transitions.",
        "dse_recommendation": "Check the documented transition exclusions before using an empty Activity Log interval to close an availability investigation.",
        "primary_source": {
            "name": "Azure Resource Health overview - Azure Service Health | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/service-health/resource-health-overview",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Resource Health does not record transitions into Unknown in the Activity Log. It also omits certain transitions out of Unknown, including when the resource returns to its prior health state or when the transition is the first one.</p>\n<p>For VMs, a healthy-to-unhealthy-to-healthy sequence is omitted when the unhealthy interval is under 35 seconds. Unknown itself means Resource Health has lacked information for more than ten minutes; it is not a definitive diagnosis of the resource&#8217;s actual condition. <a href=\"https://learn.microsoft.com/en-us/azure/service-health/resource-health-overview\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Identify the resource, observed interval and the evidence source being searched. Keep Resource Health state, Activity Log entries and application behavior as separate observations.</p>\n<h2>DSE recommendation</h2>\n<p>DSE recommends including these exclusions in the incident timeline review. Compare the reported symptom with available resource history and workload observations before concluding that the platform saw no change. Label a logging gap as a limitation rather than translating it into either confirmed health or confirmed outage. Do not infer a root cause from an Unknown state alone.</p>\n<h2>Verification</h2>\n<p>For an approved investigation or controlled exercise, retain the actual health view, event search scope and application timestamps. Check whether the observed sequence falls within a documented exclusion. Record what each source establishes and what remains unresolved. If no event is available, close the issue only from sufficient independent operational evidence, not from the assumption that every short or unknown-state transition must have produced an Activity Log record.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/service-health/resource-health-overview\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Azure Resource Health overview</a>. Source retrieved September 9, 2026.</p>",
        "content_text": "Source facts\nResource Health does not record transitions into Unknown in the Activity Log. It also omits certain transitions out of Unknown, including when the resource returns to its prior health state or when the transition is the first one.\nFor VMs, a healthy-to-unhealthy-to-healthy sequence is omitted when the unhealthy interval is under 35 seconds. Unknown itself means Resource Health has lacked information for more than ten minutes; it is not a definitive diagnosis of the resource’s actual condition. Microsoft Learn.\nApplicability\nIdentify the resource, observed interval and the evidence source being searched. Keep Resource Health state, Activity Log entries and application behavior as separate observations.\nDSE recommendation\nDSE recommends including these exclusions in the incident timeline review. Compare the reported symptom with available resource history and workload observations before concluding that the platform saw no change. Label a logging gap as a limitation rather than translating it into either confirmed health or confirmed outage. Do not infer a root cause from an Unknown state alone.\nVerification\nFor an approved investigation or controlled exercise, retain the actual health view, event search scope and application timestamps. Check whether the observed sequence falls within a documented exclusion. Record what each source establishes and what remains unresolved. If no event is available, close the issue only from sufficient independent operational evidence, not from the assumption that every short or unknown-state transition must have produced an Activity Log record.\nOfficial references\nMicrosoft Learn: Azure Resource Health overview. Source retrieved September 9, 2026.",
        "content_markdown": "## Source facts\n\nResource Health does not record transitions into Unknown in the Activity Log. It also omits certain transitions out of Unknown, including when the resource returns to its prior health state or when the transition is the first one.\n\nFor VMs, a healthy-to-unhealthy-to-healthy sequence is omitted when the unhealthy interval is under 35 seconds. Unknown itself means Resource Health has lacked information for more than ten minutes; it is not a definitive diagnosis of the resource’s actual condition. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/service-health/resource-health-overview).\n\n## Applicability\n\nIdentify the resource, observed interval and the evidence source being searched. Keep Resource Health state, Activity Log entries and application behavior as separate observations.\n\n## DSE recommendation\n\nDSE recommends including these exclusions in the incident timeline review. Compare the reported symptom with available resource history and workload observations before concluding that the platform saw no change. Label a logging gap as a limitation rather than translating it into either confirmed health or confirmed outage. Do not infer a root cause from an Unknown state alone.\n\n## Verification\n\nFor an approved investigation or controlled exercise, retain the actual health view, event search scope and application timestamps. Check whether the observed sequence falls within a documented exclusion. Record what each source establishes and what remains unresolved. If no event is available, close the issue only from sufficient independent operational evidence, not from the assumption that every short or unknown-state transition must have produced an Activity Log record.\n\n## Official references\n\n[Microsoft Learn: Azure Resource Health overview](https://learn.microsoft.com/en-us/azure/service-health/resource-health-overview). Source retrieved September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-292-allow-for-resource-health-transitions-that-never-enter-the-activity-log/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-292-allow-for-resource-health-transitions-that-never-enter-the-activity-log/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-292-allow-for-resource-health-transitions-that-never-enter-the-activity-log/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Allow for Resource Health transitions that never enter the Activity Log",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-292-allow-for-resource-health-transitions-that-never-enter-the-activity-log/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-292-allow-for-resource-health-transitions-that-never-enter-the-activity-log/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-292-allow-for-resource-health-transitions-that-never-enter-the-activity-log/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-292-allow-for-resource-health-transitions-that-never-enter-the-activity-log/",
                "headline": "Allow for Resource Health transitions that never enter the Activity Log",
                "description": "Resource Health's documented logging exclusions prevent the Activity Log from being a complete record of every observed state change.",
                "abstract": "Resource Health's documented logging exclusions prevent the Activity Log from being a complete record of every observed state change.",
                "articleBody": "Source facts\nResource Health does not record transitions into Unknown in the Activity Log. It also omits certain transitions out of Unknown, including when the resource returns to its prior health state or when the transition is the first one.\nFor VMs, a healthy-to-unhealthy-to-healthy sequence is omitted when the unhealthy interval is under 35 seconds. Unknown itself means Resource Health has lacked information for more than ten minutes; it is not a definitive diagnosis of the resource’s actual condition. Microsoft Learn.\nApplicability\nIdentify the resource, observed interval and the evidence source being searched. Keep Resource Health state, Activity Log entries and application behavior as separate observations.\nDSE recommendation\nDSE recommends including these exclusions in the incident timeline review. Compare the reported symptom with available resource history and workload observations before concluding that the platform saw no change. Label a logging gap as a limitation rather than translating it into either confirmed health or confirmed outage. Do not infer a root cause from an Unknown state alone.\nVerification\nFor an approved investigation or controlled exercise, retain the actual health view, event search scope and application timestamps. Check whether the observed sequence falls within a documented exclusion. Record what each source establishes and what remains unresolved. If no event is available, close the issue only from sufficient independent operational evidence, not from the assumption that every short or unknown-state transition must have produced an Activity Log record.\nOfficial references\nMicrosoft Learn: Azure Resource Health overview. Source retrieved September 9, 2026.",
                "datePublished": "2026-09-10T00:27:04+00:00",
                "dateModified": "2026-09-10T01:23:49+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-292-allow-for-resource-health-transitions-that-never-enter-the-activity-log/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-292-allow-for-resource-health-transitions-that-never-enter-the-activity-log/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Allow for Resource Health transitions that never enter the Activity Log"
                },
                "articleSection": [
                    "Cybersecurity",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "Cybersecurity",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 245,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Azure Resource Health overview - Azure Service Health | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/service-health/resource-health-overview"
                }
            }
        ]
    }
}