Anomalies History (Blueprint)

Use the Anomalies History page to monitor anomalies within a specified time period. Use advanced filtering options enable precise monitoring of anomaly history.

Use the history page to track trends, focus on specific intervals, and analyze historical occurrences of anomalies for improved troubleshooting and analysis. Anomaly history complements real-time anomaly detection (Current State) by offering historical context.

To view anomaly history in the GUI:

Select a blueprint and navigate to Anomalies > History within the blueprint.

Network monitoring dashboard showing historical anomalies. Tabs include Dashboard, Anomalies, Analytics, and others. Active tab displays a line graph with time and severity data, filter options for anomaly types and time range, and a detailed table with node, type, role, service, and metrics.

View Anomaly History

The default table displays anomaly data starting from the most recent saved event. Select a specific section of the graph to choose a timestamp and populate the table with anomaly data from the selected timestamp. Click on the Reset button above the graph to reset the selected timestamp.

Hover over the chart to display an overlay with additional details.

Network analytics dashboard showing a time-series graph with metrics like Route Table and BGP, a tooltip displaying timestamp and values, a table with node details and intent mismatches, dropdowns for anomaly types and time ranges, and tabs for Current State and History.

Use the drop-down menu and select a time duration to adjust the graph results. Scroll with your mouse wheel to navigate in or out through time on the graph.

Dashboard interface with a time-series graph showing data trends over a timeline. Dropdown menu labeled Last 12 Hours allows selection of time duration. History tab selected. Graph includes colored lines, shaded areas, and labels. Annotation highlights dropdown menu with instruction to select time duration. Top-right label shows Persisted 30 days and 1.07 MB data storage.

Refine with Filters

Further refine your anomaly search using filters. You can use one or both available filtering methods. The filtered results display in both the anomaly timeline graph and anomalies table.

The search query filters by the system ID. Locate the system ID under the device name in the Node column of the anomalies table. Select a search parameter from the drop-down menu to apply to your search. The search parameters include or exclude specific system IDs from the results displayed in the anomalies table. Enter a system ID into the field next to the drop-down menu and select Apply.

  • Select an appropriate search parameter, then input a System ID in the query to narrow down the results.

Use the Anomaly types filter to show or hide service anomalies by type. The filtered results are displayed in the anomalies table.

  • Filter by specific anomaly using the Anomaly types filter.

User interface for filtering data, featuring search query input, dropdowns for anomaly type and time range selection, and apply and clear buttons. Red annotations highlight key filters.

Expanded Anomaly Timeline

Use the anomaly's historical timeline to perform troubleshooting activities and correlate the anomaly with network changes or events that occurred over a specific period. You can view the anomaly's start time and its duration. Additional details are displayed in the expanded anomaly timeline window.

To show an expanded anomaly timeline:

  1. Select a timestamp on the anomaly timeline graph. This will populate the table with the Historical Timeline column.

  2. Click Show Anomaly Timeline in the Historical Timeline column of the table.

  3. Click Show expand anomaly timeline to open the anomaly timeline in a new window.

Table displaying network nodes, interfaces, and statuses with columns for Node, Hostname, Type, Role, Service, Additional Details, Intent Mismatch, and Historical Timeline. Red arrows annotate how to expand anomaly timelines.

Click any location on the anomaly timeline to see additional anomaly data. Click on the Reset button to reset the timestamp selection.

Historical timeline showing a BGP anomaly for Spine1 observed on February 23 2026 at 15:17:07 with expected value up and actual value down. Anomaly started on January 29 2026 lasting over 25 days. Key details include ipv4 address family destination ASN 64515 destination IP 192.168.0.3 and source ASN 64512.

View Anomalies by Node

Note: Clicking on a device redirects you from the anomalies history page. The anomalies displayed under telemetry only provide anomalies reflecting the current state.

Click on a device from the anomaly table Node column to go to its telemetry page. The Anomalies tab under Telemetry displays all related device anomalies

You can also reach the device telemetry section by:

  1. Use the left navigation menu in the GUI. Navigate to Devices > Managed Devices. Click the Management IP of the device to view.

  2. Click the Telemetry tab to open the Telemetry details page

  3. Click on the Anomalies tab Telemetry > Anomalies. All anomalies (indicated in red) from the telemetry services are aggregated under the Anomalies tab.

Network monitoring dashboard with Active tab selected. Telemetry section open showing categories like Anomalies and Utilization. Anomalies table displays data on nodes, roles, services, and intent mismatch issues with timestamps.