# Check the any-tag cohort behind a managed-application metrics view

> Does listing several tags require a managed-application metric resource to match all of them?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-350-check-the-any-tag-cohort-behind-a-managed-application-metrics-view/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:26:06+00:00
- Modified: 2026-09-10T01:40:04+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Does listing several tags require a managed-application metric resource to match all of them?

## Potentially affected

Azure Managed Applications using a viewDefinition.json Metrics view.

## DSE recommendation

DSE recommends comparing the resource-type constraint and each tag alternative with the intended monitoring population.

## Article

## Source facts

A managed-application Metrics view can chart data from its resources through Azure Monitor Metrics. Within a metric definition, resourceType selects the resource type. The resourceTagFilter list uses OR matching and is applied after the resource-type filter; multiple listed tags do not express an all-tags condition. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-resource-manager/managed-applications/concepts-view-definition).

## Applicability

Review this configuration when a chart appears to include a broader resource cohort than its owner intended. Write the intended resource membership down before interpreting the plotted metric. Keep the filter question separate from the chosen metric’s aggregation and the chart’s visual presentation.

## DSE recommendation

DSE recommends comparing the resource-type constraint and each tag alternative with the intended monitoring population. If the intended requirement is a conjunction of tags, do not approve the existing list on that assumption. Reconsider the view design with the monitoring owner and document the expected membership. Avoid changing tags across production resources merely to force an unexplained chart into the expected shape.

## Verification

Use a small approved set with the same resource type and distinguishable tag combinations, plus a resource of a different type. Compare which resources contribute under one tag and under the combined list. Keep the observed membership beside the view definition and explain any discrepancy before relying on the chart for an operational decision. Record actual results; the documented matching rule does not establish the state of a deployed view.

## Official references

[Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-resource-manager/managed-applications/concepts-view-definition). Source retrieved September 9, 2026.

## Primary reference

- Name: Overview of view definition - Azure Managed Applications | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/azure-resource-manager/managed-applications/concepts-view-definition
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Check the any-tag cohort behind a managed-application metrics view,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-350-check-the-any-tag-cohort-behind-a-managed-application-metrics-view/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
