# Keep VM watch process CPU percentages tied to their denominator

> Why can two VM watch process CPU metrics report different percentages for the same process?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-028-keep-vm-watch-process-cpu-percentages-tied-to-their-denominator/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:31:28+00:00
- Modified: 2026-09-10T00:32:00+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

Why can two VM watch process CPU metrics report different percentages for the same process?

## Potentially affected

Azure VMs and scale sets evaluating the VM watch preview's process CPU measurements.

## DSE recommendation

Label process CPU charts with the exact VM watch metric and denominator.

## Article

## Source facts

VM watch is a preview that runs configurable in-guest health checks and is delivered through the Application Health VM extension. Its ProcessCPUCoreUsage metric expresses instantaneous process usage against one CPU core, whereas ProcessCPUMachineUsage expresses process usage against the machine’s total CPU. MachineTotalCpuUsage describes the VM’s total instantaneous CPU utilization. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/virtual-machines/azure-vm-watch).

## Applicability

Use this interpretation check when building process-level dashboards or comparing a process chart with a whole-machine chart. Preserve the metric names in the evidence instead of presenting every percentage under a generic CPU heading.

## DSE recommendation

Label process CPU charts with the exact VM watch metric and denominator. Have the monitoring owner explain which question each chart answers: how much of one core the process is consuming, how much of the machine it is consuming, or how busy the entire VM is. Review any proposed alert threshold against that selected measurement. Do not transfer a threshold merely because both charts use a percent sign.

## Verification

Collect the relevant signals over the same controlled workload interval and inspect them together. Record the VM configuration and the exact measurement being reviewed. If a chart differs from expectations, check its selected metric before diagnosing a workload regression. Treat this as a preview evaluation, and verify the actual deployed collector configuration rather than assuming every default signal is present.

## Official references

[Microsoft Learn: VM watch: Enhancing VM health monitoring preview](https://learn.microsoft.com/en-us/azure/virtual-machines/azure-vm-watch). Source reviewed September 9, 2026.

## Primary reference

- Name: Azure VM Watch - Azure Virtual Machines | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/virtual-machines/azure-vm-watch
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Keep VM watch process CPU percentages tied to their denominator,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-028-keep-vm-watch-process-cpu-percentages-tied-to-their-denominator/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
