# Do not read an Application Map filter percentile as request latency

> Does P90 beside an Application Map average-duration filter describe the slowest tenth of individual requests?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-203-do-not-read-an-application-map-filter-percentile-as-request-latency/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:28:33+00:00
- Modified: 2026-09-10T01:20:45+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Explainer
- DSE priority: Information
- Topics: Cybersecurity, IT
- Reading time: 2 minutes

## What you need to know

Does P90 beside an Application Map average-duration filter describe the slowest tenth of individual requests?

## Potentially affected

Azure Monitor Application Map connector filters for distributed applications.

## DSE recommendation

State that the filter ranks connector averages, then inspect request evidence before making a latency conclusion.

## Article

## Source facts

Application Map’s average-duration connector filter measures the mean duration of calls across each connector. A P90 label on a suggested filter value describes the distribution of connectors, irrespective of how many calls each represents. Microsoft’s 200-millisecond example means that 90 percent of connectors have an average duration below that value, not that 90 percent of all requests completed within it. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-monitor/app/app-map).

Map filters also apply in sequence from left to right. Once an earlier filter removes a node or connector, a later filter cannot bring it back. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-monitor/app/app-map).

## Applicability

Review Azure Monitor Application Map connector filters for distributed applications. Keep the map-selection statistic separate from a request-level latency objective or an application’s end-to-end response time.

## DSE recommendation

DSE recommends labeling a saved investigation view with the connector statistic being selected. Compare low-volume and high-volume connectors before treating the percentile label as a workload-wide result. Use the filtered map to choose where to investigate, then examine the relevant request and dependency evidence. Preserve the filter order so another operator can reproduce why a connection was visible or absent.

## Verification

Choose two connectors with different call volumes and compare their displayed averages with the selected filter boundary. Review the underlying calls for the actual latency question. Remove filters in a controlled comparison to identify excluded paths. Do not report a request percentile merely by copying the P90 label from a map filter.

## Official references

[Microsoft Learn: Application Map](https://learn.microsoft.com/en-us/azure/azure-monitor/app/app-map).

## Primary reference

- Name: Application map in Azure Application Insights - Azure Monitor | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/azure-monitor/app/app-map
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Do not read an Application Map filter percentile as request latency,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-203-do-not-read-an-application-map-filter-percentile-as-request-latency/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
