Investigate the anomaly
Open the anomaly
Open the anomaly and start an investigation:
- Select Anomalies () from the navigation menu.
- Find the service showing as Anomalous.
- Select Investigate (or View Investigation if a Canvas investigation is already underway).
Confirm the gap on the Presence chart
On the service’s Presence view, locate the highlighted gap on the chart, which shows the service’s event volume over time.
Note when the data stream stopped and whether it has resumed.
Rule out an expected cause
Check whether the gap lines up with a planned deployment, a maintenance window, or a deliberate service shutdown.
A gap that starts right after a deploy points toward the deploy as the likely cause.
Check the Canvas investigation
If auto-investigate is turned on for the service, review the Canvas investigation for related changes, such as a recent deploy or a dependency also showing anomalies.If auto-investigate isn’t turned on, check the Anomalies list for related services that are also marked as Anomalous and may share the same cause.
Make the call
With the gap confirmed and a likely cause identified, you have what you need to decide how to respond:- If the gap doesn’t match a planned change, or a dependent service is also affected, escalate to the configured recipients and treat it as a live incident.
- If the gap matches a planned deployment or maintenance window, you can close the investigation with confidence rather than escalating further.