{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-311-do-not-use-performance-anomaly-email-silence-as-a-real-time-health-check/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-311-do-not-use-performance-anomaly-email-silence-as-a-real-time-health-check/",
        "slug": "dse-20260909-311-do-not-use-performance-anomaly-email-silence-as-a-real-time-health-check",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-311-do-not-use-performance-anomaly-email-silence-as-a-real-time-health-check/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-311-do-not-use-performance-anomaly-email-silence-as-a-real-time-health-check.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-311-do-not-use-performance-anomaly-email-silence-as-a-real-time-health-check/"
        },
        "title": "Do not use performance-anomaly email silence as a real-time health check",
        "summary": "Does the absence of another Application Insights performance-anomaly email mean that the issue recovered?",
        "format": {
            "slug": "briefing",
            "name": "Briefing"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "continuity-recovery",
            "label": "Continuity & recovery",
            "alt": "Paired infrastructure paths converging on a stable recovered service.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:26:45+00:00",
        "modified_at": "2026-09-10T01:40:02+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 234,
        "potentially_affected": "Application Insights applications using the documented smart-detection performance-anomaly notifications.",
        "dse_recommendation": "Use the notification to open an investigation, and assign separate evidence for present health and recovery.",
        "primary_source": {
            "name": "Smart detection - performance anomalies - Azure Monitor | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/azure-monitor/alerts/smart-detection-performance",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Performance-anomaly analysis runs daily against the preceding UTC day and needs at least eight days of sufficient telemetry to establish normal behavior. Microsoft does not promise to detect every abnormal condition or replace metric alerts. An issue produces one message, not repeated reminders; a persistent issue is updated in the smart-detection feed. Performance-anomaly emails are limited to one per resource per day when a new issue exists. <a href=\"https://learn.microsoft.com/en-us/azure/azure-monitor/alerts/smart-detection-performance\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>This interpretation concerns performance-anomaly notifications, not an application&#8217;s real-time availability contract. Separate a historical detection, its email delivery, and the evidence that the application is currently responding acceptably.</p>\n<h2>DSE recommendation</h2>\n<p>Use the notification to open an investigation, and assign separate evidence for present health and recovery. Give the investigator the affected operation, observed period and relevant deployment history. Do not close the investigation because tomorrow&#8217;s mailbox contains no reminder. Identify the checks that will demonstrate recovery and retain an owner until those checks have been evaluated.</p>\n<h2>Verification</h2>\n<p>Compare the notification&#8217;s detection period with current application measurements rather than treating them as simultaneous observations. Inspect the feed for the issue&#8217;s updated status and record the independent service checks used to reach a recovery conclusion. When assessing a newly instrumented application, document whether enough representative telemetry exists for the stated learning period. Keep missing notification, missing telemetry and successful recovery as different findings.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/azure-monitor/alerts/smart-detection-performance\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Smart detection performance anomalies</a>. Source reviewed September 9, 2026.</p>",
        "content_text": "Source facts\nPerformance-anomaly analysis runs daily against the preceding UTC day and needs at least eight days of sufficient telemetry to establish normal behavior. Microsoft does not promise to detect every abnormal condition or replace metric alerts. An issue produces one message, not repeated reminders; a persistent issue is updated in the smart-detection feed. Performance-anomaly emails are limited to one per resource per day when a new issue exists. Microsoft Learn.\nApplicability\nThis interpretation concerns performance-anomaly notifications, not an application’s real-time availability contract. Separate a historical detection, its email delivery, and the evidence that the application is currently responding acceptably.\nDSE recommendation\nUse the notification to open an investigation, and assign separate evidence for present health and recovery. Give the investigator the affected operation, observed period and relevant deployment history. Do not close the investigation because tomorrow’s mailbox contains no reminder. Identify the checks that will demonstrate recovery and retain an owner until those checks have been evaluated.\nVerification\nCompare the notification’s detection period with current application measurements rather than treating them as simultaneous observations. Inspect the feed for the issue’s updated status and record the independent service checks used to reach a recovery conclusion. When assessing a newly instrumented application, document whether enough representative telemetry exists for the stated learning period. Keep missing notification, missing telemetry and successful recovery as different findings.\nOfficial references\nMicrosoft Learn: Smart detection performance anomalies. Source reviewed September 9, 2026.",
        "content_markdown": "## Source facts\n\nPerformance-anomaly analysis runs daily against the preceding UTC day and needs at least eight days of sufficient telemetry to establish normal behavior. Microsoft does not promise to detect every abnormal condition or replace metric alerts. An issue produces one message, not repeated reminders; a persistent issue is updated in the smart-detection feed. Performance-anomaly emails are limited to one per resource per day when a new issue exists. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-monitor/alerts/smart-detection-performance).\n\n## Applicability\n\nThis interpretation concerns performance-anomaly notifications, not an application’s real-time availability contract. Separate a historical detection, its email delivery, and the evidence that the application is currently responding acceptably.\n\n## DSE recommendation\n\nUse the notification to open an investigation, and assign separate evidence for present health and recovery. Give the investigator the affected operation, observed period and relevant deployment history. Do not close the investigation because tomorrow’s mailbox contains no reminder. Identify the checks that will demonstrate recovery and retain an owner until those checks have been evaluated.\n\n## Verification\n\nCompare the notification’s detection period with current application measurements rather than treating them as simultaneous observations. Inspect the feed for the issue’s updated status and record the independent service checks used to reach a recovery conclusion. When assessing a newly instrumented application, document whether enough representative telemetry exists for the stated learning period. Keep missing notification, missing telemetry and successful recovery as different findings.\n\n## Official references\n\n[Microsoft Learn: Smart detection performance anomalies](https://learn.microsoft.com/en-us/azure/azure-monitor/alerts/smart-detection-performance). Source reviewed September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-311-do-not-use-performance-anomaly-email-silence-as-a-real-time-health-check/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-311-do-not-use-performance-anomaly-email-silence-as-a-real-time-health-check/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-311-do-not-use-performance-anomaly-email-silence-as-a-real-time-health-check/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Do not use performance-anomaly email silence as a real-time health check",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-311-do-not-use-performance-anomaly-email-silence-as-a-real-time-health-check/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-311-do-not-use-performance-anomaly-email-silence-as-a-real-time-health-check/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-311-do-not-use-performance-anomaly-email-silence-as-a-real-time-health-check/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-311-do-not-use-performance-anomaly-email-silence-as-a-real-time-health-check/",
                "headline": "Do not use performance-anomaly email silence as a real-time health check",
                "description": "Does the absence of another Application Insights performance-anomaly email mean that the issue recovered?",
                "abstract": "Does the absence of another Application Insights performance-anomaly email mean that the issue recovered?",
                "articleBody": "Source facts\nPerformance-anomaly analysis runs daily against the preceding UTC day and needs at least eight days of sufficient telemetry to establish normal behavior. Microsoft does not promise to detect every abnormal condition or replace metric alerts. An issue produces one message, not repeated reminders; a persistent issue is updated in the smart-detection feed. Performance-anomaly emails are limited to one per resource per day when a new issue exists. Microsoft Learn.\nApplicability\nThis interpretation concerns performance-anomaly notifications, not an application’s real-time availability contract. Separate a historical detection, its email delivery, and the evidence that the application is currently responding acceptably.\nDSE recommendation\nUse the notification to open an investigation, and assign separate evidence for present health and recovery. Give the investigator the affected operation, observed period and relevant deployment history. Do not close the investigation because tomorrow’s mailbox contains no reminder. Identify the checks that will demonstrate recovery and retain an owner until those checks have been evaluated.\nVerification\nCompare the notification’s detection period with current application measurements rather than treating them as simultaneous observations. Inspect the feed for the issue’s updated status and record the independent service checks used to reach a recovery conclusion. When assessing a newly instrumented application, document whether enough representative telemetry exists for the stated learning period. Keep missing notification, missing telemetry and successful recovery as different findings.\nOfficial references\nMicrosoft Learn: Smart detection performance anomalies. Source reviewed September 9, 2026.",
                "datePublished": "2026-09-10T00:26:45+00:00",
                "dateModified": "2026-09-10T01:40:02+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-311-do-not-use-performance-anomaly-email-silence-as-a-real-time-health-check/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-311-do-not-use-performance-anomaly-email-silence-as-a-real-time-health-check/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Do not use performance-anomaly email silence as a real-time health check"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Briefing",
                    "Information priority"
                ],
                "genre": "Briefing",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 234,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Smart detection - performance anomalies - Azure Monitor | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/azure-monitor/alerts/smart-detection-performance"
                }
            }
        ]
    }
}