---
sourceDocument: Brazil IT Operations Management
sourceDocumentLink: https://www.servicenow.com/docs/r/it-operations-management

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Types of anomalous behavior

# Types of anomalous behavior in Health Log Analytics {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Types of anomalous behavior in Health Log Analytics

Health Log Analytics in ServiceNow detects anomalous behavior in Configuration Items (CIs) or services by monitoring log streams and establishing baselines for patterns, metrics, and gauges over various time intervals such as hourly, daily, and weekly.
Behavior that deviates from these learned baselines is flagged as anomalous, enabling early identification of potential issues indicated by unusual spikes or drops in log message frequency or values.
Show full answer Show less  

## Types of Log Properties

* **Pattern:** Repeating values or rates in text, time, or relationships within logs.
* **Meter:** Numeric or text values like status codes or response codes.
* **Gauge:** Continuously reported numerical values representing resource consumption, such as CPU or memory usage.

## How Anomalies Are Displayed

The Anomaly card in Health Log Analytics visualizes anomalous activity by comparing recent events against expected behavior baselines, including values from one day and one week prior. For example, a sudden spike in an otherwise inactive log pattern triggers an alert by showing deviation from the baseline rate of events per minute.

## Kinds of Anomalies and Their Significance

* **New Behavior:** Detection of previously unseen log patterns, indicating novel or emergent issues. This alert type does not include a chart.
* **Signal Dead/Stopped Appearing:** Complete absence of log data or patterns from a source for at least five minutes, signaling potential outages or failures.
* **Signal Alive/Appearing Again:** Reappearance of log data from a previously "dead" source.
* **Anomaly Above or Below Average:** Deviations in activity levels from expected baselines across patterns, meters, or gauges, such as unusual keyword or severity metric changes.
* **Baseline Reference Increase or Decrease:** Significant rises or drops in log property values or volumes compared to one-hour or one-week baselines.
* **Correlation of Severity and Keyword Alerts:** Increases in specific severity levels or keyword occurrences, highlighting correlated issues.

ServiceNow customers can leverage these anomaly detections to proactively monitor system health, quickly identify unusual log behaviors, and respond to potential service issues before they escalate.  
Anomalous behavior in a CI or a service can indicate an important issue. For example, a spike in the frequency or number of messages of a particular type can indicate a problem.
To build models of expected behavior, Health Log Analytics monitors the log stream to learn baselines for patterns, metrics, and gauges over various time periods. Time periods can be hourly, daily, weekly, or unlimited. Behavior that departs from
the learned models is considered anomalous behavior.

## Types of log property {#hla-op-anomalous-behavior-types__section_tv4_dkx_nnb}

Pattern
:   A pattern is a value or rate that repeats, whether in text, time, or relationships.

Meter
:   A meter property is a numeric or text value. For example, a status code, a response code, an action, or a pattern.

Gauge
:   A gauge property has a numerical value that is reported continuously. Gauge properties represent operations that consume resources. For example, CPU usage, memory usage, or response time.

## How anomalies appear in Health Log Analytics {#hla-op-anomalous-behavior-types__section_pnk_rnh_f4b}

The Anomaly card illustrates the anomalous activity that led to the alert. The chart shows:

* Recent anomalous activity
* Expected behavior (the learned baseline)
* Baseline values from one day earlier
* Baseline values from the previous week
{#hla-op-anomalous-behavior-types__ul_bhk_n3p_3nb}  
In this example, the system tracks the baseline rate (the average number of events per minute) for a specific log pattern. When this typically inactive log generates a spike in events, the system detects the deviation from the baseline and generates an alert.Figure 1. Anomaly card

## Kinds of anomalies {#hla-op-anomalous-behavior-types__section_rq5_dkx_nnb}

{#hla-op-anomalous-behavior-types__table_kl3_dcv_hnb__entry__2}

| Behavior | Description |
|-|-|
| New behavior | A pattern that has not ever been seen. The New Behavior alert type does not display a chart. |
| Signal dead/Stopped appearing | All pattern or log data from a source has stopped. There has been no signal for at least five minutes. |
| Signal alive/Appearing again | A pattern or log data from a "dead" source is appearing again​. For a baseline of one hour, a pattern is "dead" if it appears less than once per minute. |
| Anomaly above average or below average | Activity that deviates from expected baseline behavior for pattern or meter or gauge metrics, such as keywords metrics or severity metrics. |
| Baseline reference​ increase or decrease | An increase or decrease in the value or volume of a log property as compared to the one-hour or one-week baseline. |
| Correlation of severity and keyword alerts | An increase in the volume of a severity level or keyword. |
[Table 1. Some of the kinds of anomalies]

{#hla-op-anomalous-behavior-types__table_kl3_dcv_hnb}

