# Keep Service Fabric health output filters separate from evaluation policy

> Can a filtered Service Fabric health result still reflect events that are absent from its displayed list?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-382-keep-service-fabric-health-output-filters-separate-from-evaluation-policy/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:25:34+00:00
- Modified: 2026-09-10T02:01:56+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 1 minutes

## What you need to know

Can a filtered Service Fabric health result still reflect events that are absent from its displayed list?

## Potentially affected

Service Fabric cluster health queries with event, node or application output filters.

## DSE recommendation

DSE recommends recording the query's output filters and evaluation policies as separate review inputs.

## Article

## Source facts

Service Fabric’s cluster-health filters limit the events, nodes and applications returned, but all of them still participate in aggregated health evaluation. Health policies, rather than those output filters, govern the evaluation. Unhealthy evaluations show the first reason for the resulting state and may omit other contributing events. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/service-fabric/service-fabric-view-entities-aggregated-health).

## Applicability

Apply this distinction when a reduced response seems inconsistent with the cluster’s reported state. Compare the selected output with the full evaluation scope. Do not treat an empty filtered list as evidence that the underlying cluster has no unhealthy entities.

## DSE recommendation

DSE recommends recording the query’s output filters and evaluation policies as separate review inputs. Preserve the policy settings when comparing two queries so an output change is not confused with a changed health decision. Use the initial unhealthy evaluation to choose where to investigate, then examine the relevant child entities and their reports rather than closing the incident after the first explanation.

## Verification

In a read-only comparison, request the same cluster under the same policies with broader and narrower output filters. Check the returned entities and aggregate state separately. Drill into the reported unhealthy children to collect other contributing events. Retain the query parameters with each result; a short response should remain traceable to the scope it omitted.

## Official references

[Microsoft Learn](https://learn.microsoft.com/en-us/azure/service-fabric/service-fabric-view-entities-aggregated-health). Source retrieved September 9, 2026.

## Primary reference

- Name: How to view Azure Service Fabric entities' aggregated health - Azure Service Fabric | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/service-fabric/service-fabric-view-entities-aggregated-health
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Keep Service Fabric health output filters separate from evaluation policy,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-382-keep-service-fabric-health-output-filters-separate-from-evaluation-policy/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
