Metric-to-Metric Correlation¶
When an anomaly fires, the correlation engine automatically checks what other metrics also deviated in the same time window. The alert includes correlated metrics — for example, "CPU spiked and 3 other metrics were also anomalous" — so you can tell whether an anomaly is isolated or part of a broader incident.
Correlation is available on the compact tier and above. Metrics that also show unusual behavior (z-score > 2.0) in the same window are flagged as correlated. The correlation window is configurable per subscription (1–30 minutes).
Log correlation¶
With the Log Pattern field (advanced tier and above), AI Monitor also searches OpenSearch logs for entries matching a pattern within the correlation window when an anomaly fires. By default it looks for ERROR, Exception, and FATAL entries. If your Log Processor has custom pattern rules configured, you can select one or more patterns instead (for example, secrets, slow queries, connection errors). Results appear in the anomaly detail view under "Correlated Log Entries."
This is where AI Monitor pairs with Log Processor: metric anomalies get root-cause context from your logs, and detections can correlate into AI SIEM for cross-product correlation.