# Convert Elastic SAN transaction buckets into correctly scoped average rates

> Transactions and transferred bytes need the selected interval's duration; the result is a SAN-level average, not an instantaneous per-volume peak.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-384-convert-elastic-san-transaction-buckets-into-correctly-scoped-average-rates/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:25:32+00:00
- Modified: 2026-09-10T02:01:56+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Transactions and transferred bytes need the selected interval's duration; the result is a SAN-level average, not an instantaneous per-volume peak.

## Potentially affected

Azure Elastic SAN metric reports built from Transactions, Ingress and Egress.

## DSE recommendation

Record aggregation, interval and SAN scope beside each calculated rate.

## Article

## Source facts

Microsoft calculates average Elastic SAN IOPS by dividing total transactions in a time bucket by that bucket’s seconds. Average total throughput in MB/s is the sum of Ingress and Egress bytes divided by seconds and by 1,000,000. These are interval averages, not instantaneous rates.

For Elastic SAN, Ingress is data written to the SAN and Egress is data read from it. Metrics are currently available at SAN level, not as volume-group or per-volume performance metrics; Microsoft recommends correlating workload, VM or operating-system monitoring. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/storage/elastic-san/elastic-san-metrics).

## Applicability

Identify the SAN, time range, bucket duration and aggregation selected in the report. Keep read and write direction anchored to the SAN rather than the client’s interface labels.

## DSE recommendation

DSE recommends storing the denominator and metric scope with each derived rate. Recalculate when chart granularity changes; do not keep dividing by sixty after switching away from minute buckets. Use separate workload evidence to investigate one volume instead of assigning the whole SAN’s traffic to it. Keep peaks and bucket averages distinctly labeled.

## Verification

Reproduce a selected report point from its raw transaction or byte total and interval duration. Compare the result at another supported granularity and explain expected averaging differences. Correlate a controlled workload observation without claiming the aggregate proves a particular volume’s rate. Retain the calculation inputs so another reviewer can check both units and scope.

## Official references

[Microsoft Learn: Metrics for Azure Elastic SAN](https://learn.microsoft.com/en-us/azure/storage/elastic-san/elastic-san-metrics). Source retrieved September 9, 2026.

## Primary reference

- Name: Metrics for Azure Elastic SAN | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/storage/elastic-san/elastic-san-metrics
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Convert Elastic SAN transaction buckets into correctly scoped average rates,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-384-convert-elastic-san-transaction-buckets-into-correctly-scoped-average-rates/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
