# Allow for Resource Health transitions that never enter the Activity Log

> Resource Health's documented logging exclusions prevent the Activity Log from being a complete record of every observed state change.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-292-allow-for-resource-health-transitions-that-never-enter-the-activity-log/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:27:04+00:00
- Modified: 2026-09-10T01:23:49+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Resource Health's documented logging exclusions prevent the Activity Log from being a complete record of every observed state change.

## Potentially affected

Azure Resource Health investigations using Activity Log events, including virtual-machine health transitions.

## DSE recommendation

Check the documented transition exclusions before using an empty Activity Log interval to close an availability investigation.

## Article

## Source facts

Resource Health does not record transitions into Unknown in the Activity Log. It also omits certain transitions out of Unknown, including when the resource returns to its prior health state or when the transition is the first one.

For VMs, a healthy-to-unhealthy-to-healthy sequence is omitted when the unhealthy interval is under 35 seconds. Unknown itself means Resource Health has lacked information for more than ten minutes; it is not a definitive diagnosis of the resource’s actual condition. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/service-health/resource-health-overview).

## Applicability

Identify the resource, observed interval and the evidence source being searched. Keep Resource Health state, Activity Log entries and application behavior as separate observations.

## DSE recommendation

DSE recommends including these exclusions in the incident timeline review. Compare the reported symptom with available resource history and workload observations before concluding that the platform saw no change. Label a logging gap as a limitation rather than translating it into either confirmed health or confirmed outage. Do not infer a root cause from an Unknown state alone.

## Verification

For an approved investigation or controlled exercise, retain the actual health view, event search scope and application timestamps. Check whether the observed sequence falls within a documented exclusion. Record what each source establishes and what remains unresolved. If no event is available, close the issue only from sufficient independent operational evidence, not from the assumption that every short or unknown-state transition must have produced an Activity Log record.

## Official references

[Microsoft Learn: Azure Resource Health overview](https://learn.microsoft.com/en-us/azure/service-health/resource-health-overview). Source retrieved September 9, 2026.

## Primary reference

- Name: Azure Resource Health overview - Azure Service Health | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/service-health/resource-health-overview
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Allow for Resource Health transitions that never enter the Activity Log,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-292-allow-for-resource-health-transitions-that-never-enter-the-activity-log/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
