Anomalies & Scanning
The Anomalies & Scanning section of Insights summarizes the anomalies found, their current status, and the scanning that produced them.
Before you read the numbers
What gets counted here is set by the filters, and every value follows the same reading conventions, such as what a percentage compares against and when a number reads --.
What the Section Shows
Four panels, each answering a different question about what your checks caught and the scanning that found it.
Anomaly Summary
The center of the card shows Anomalies Identified, the total number of anomalies recorded as of the report date. The ring around it is divided into the six statuses, and those six counts add up to the total, since every anomaly holds exactly one of them. Like the check breakdown, these rows report counts only, with no change percentage.
Each icon sits inside a circle tinted with the same color shown here.
| Status | Description |
|---|---|
| Active | Unresolved and not yet acknowledged or archived. These are the ones to triage, using severity, ownership, and business impact to prioritize. |
| Acknowledged | Recognized by a user but not yet resolved. Acknowledging records workflow progress. It does not assert that the underlying data is correct. |
| Resolved | Marked resolved after an outcome was documented. The status records the team's decision and does not by itself re-evaluate current source data. |
| Duplicate | Marked as a duplicate of an existing finding, so two people do not investigate the same issue. |
| Invalid | Judged not to represent a valid issue in your business context. |
| Discarded | Intentionally removed from the active workflow because the team decided not to pursue it. |
Active and Acknowledged are the open statuses. The other four are archived, and selecting any status opens the Anomalies tab on the matching list.
Hover a number to see it in full
Every count on this card is abbreviated, so 42.57K stands in for the real figure. Hovering any value above 1,000 shows the exact count written out. A value of 1,000 or less is already exact and carries no tooltip.
Containers Scanned and Records Scanned
- Containers Scanned is the number of distinct containers a Scan has covered up to the report date. A container scanned many times is counted once.
- Records Scanned is the total number of records processed by scans up to the report date.
Both carry a percentage beside the total, comparing where the count stood on the report date against where it stood at the start of the timeframe. Hovering it says which timeframe it is measured against. Unlike the Anomaly Summary breakdown above, which reports counts only, these two always show the percentage whenever the card has a value, and a count that did not move reads 0% with a grey dot instead of an arrow.
Failed Check Distribution
Failed Check Distribution is a single horizontal bar split into one segment per check rule type, each sized by how many anomalies that rule type produced. It answers which kinds of rules are failing most often, and where to look first.
A color legend below the bar names each rule type. The Top control chooses whether the 5 or the 10 most common rule types get a segment of their own, and everything past that point is combined into one All Other segment.
Hover a segment to see what it holds
The tooltip is headed by the rule type, then gives Ratio, its share of the anomalies identified, Count, how many anomalies it produced, and Importance, the weight that rule type carries. The All Other segment reports Ratio and Count only, since it bundles several rule types with different importance.
Scanning Activity
Scanning Activity charts scanning across the periods of the timeframe.
- A line tracks Scan Runs, the number of scan operations that completed successfully in each period.
- Bars show a second metric for that period, chosen from the dropdown beside the legend. The options are Anomalies Identified and Records Scanned.
Anomalies are counted on the date of the scan that produced them, so a spike in the bars lines up with the scan that found the problem.
The two use separate scales, on the left and right of the chart.
A period earns a point on the Scan Runs line only when at least one scan finished successfully in it. When nothing ran, or everything that ran failed, that period holds no value rather than a value of zero, so the line skips it and bridges the gap with a grey dashed segment. That is the same cue the Data Volume chart uses, and it is why a quiet stretch reads as a break in the line instead of a drop to the bottom of the chart.
Hover a period to read both measures at once
A single tooltip covers the whole period, so Scan Runs and whichever bar metric you have selected, Anomalies Identified or Records Scanned, appear together with the period as the heading. The period is written to match the current grouping, so the same chart reads Sep 14, 2026 when grouped by day and Q3 - 2026 when grouped by quarter, and a measure with nothing recorded for that period is left out of the tooltip rather than shown as zero.