Investigating an Anomaly #
When an anomaly is detected, here is a practical investigation process.
Step 1: Assess the Anomaly #
Open the anomaly detail from the Anomaly Detection page. Note:
– Which metric is affected?
– What is the deviation magnitude?
– When was it detected?
– Spike (too high) or drop (too low)?
Step 2: Cross-Reference with Other Metrics #
Navigate to the relevant analytics page to see the full picture:
| Anomaly Metric | Go To Page |
|---|---|
| MRR drop | Revenue Analytics |
| Churn rate spike | Customer Analytics |
| Download volume spike | Download Analytics |
| License activation drop | License Analytics |
Look for related anomalies that might explain the one you are investigating.
Step 3: Check the Events Timeline #
Go to DDLS > Real-Time Dashboard and look at the event feed around the time the anomaly was detected. Were there unusual license deletions? Failed activations? A flood of downloads?
Step 4: Correlate with External Events #
Consider whether any of the following happened around the anomaly date:
– A new product version was released (expected download spike)
– A promotional email was sent (expected spike in all metrics)
– A payment processor had an outage (would cause payment failures, churn spike)
– A major customer cancelled (would cause MRR drop)
Step 5: Document and Close #
Once you understand the cause, resolve or dismiss the anomaly with a note. This keeps your anomaly log meaningful for future reference.
