Automated Anomaly Detection for Message Volume identifies unusual increases or decreases in EDI transaction activity for trading partner and document-type combinations.
The system evaluates historical message volume patterns in Cleo Integration Cloud (CIC) and surfaces activity that falls outside the expected range. This helps identify missing or unexpected transaction activity that indicate integration, partner, or upstream system issues, without requiring manual thresholds or ongoing configuration.
What anomaly detection monitors
Anomaly detection evaluates message volume only. It does not consider transaction content, transaction success or failure, or intraday timing patterns (for example, time-of-day or hourly distribution). Detection focuses on whether expected transaction activity occurs.
How detection works
For each eligible trading partner and document type, the system establishes an expected volume range based on historical activity.
A daily detection process compares actual message counts against this range. When volume falls outside it, the system records an anomaly.
Anomaly detection highlights what changed in message volume. It does not determine the cause of the change or recommend corrective actions.
Eligibility and guardrails
Anomaly detection runs automatically for trading partner and document-type combinations that meet minimum data thresholds.
| Requirement | Detail |
|---|---|
| Historical data | At least 6 months of transaction history for the partner and document-type combination |
| Transaction volume | Approximately 300 transactions per year (about one per day) |
| Eligibility persistence | Once a combination becomes eligible, it continues to be evaluated going forward |
| Low-volume combinations | Combinations with less than 12 months of history may be included with a data quality disclaimer indicating results may be less precise |
Monitoring scope
By default, anomaly detection monitors all eligible trading partner and document-type combinations.
Filters in Network Global Settings Anomalies allow you to narrow the scope when needed.
| Setting | Options |
|---|---|
| Partner filter | All Partners | All Partners Except… | Only from Partners… |
| Document type filter | All Document Types | Selected EDI document types only |
| Notification delivery | Daily digest email with configurable delivery time and time zone |
Where you see anomalies
Detected anomalies are available in two places within CIC.
Activity > Anomalies
This is the primary surface for reviewing anomaly data. From this view you can:
- View anomalies by trading partner and document type
- Compare actual message counts to expected volume ranges
- Identify whether volume was higher or lower than expected
- Filter by partner, document type, time range, and anomaly direction
A timeline view provides additional context by showing anomalies alongside historical message volume, helping distinguish trends from isolated deviations.
See View detected message‑volume anomalies for navigation and filtering details.
Activity Dashboard — Volume Anomalies widget
The Global Activity Dashboard includes a Volume Anomalies widget that shows the total number of detected anomalies within the selected timeframe, along with the top contributing partners and document types.
Selecting the widget opens Activity > Anomalies, scoped to the same timeframe. This provides a quick way to determine whether anomaly activity is elevated without navigating away from the dashboard.
Notifications
CIC sends a daily email summary of anomalies detected during the previous 24-hour period. Each email includes:
- Total anomaly count for the period
- Per-partner summaries, including document type, direction (higher or lower than expected), and actual versus expected volume
- A direct link to Activity > Anomalies for full review
Notifications are delivered within one hour after the daily detection process completes.
Administrators configure delivery time and time zone in Network > Global Settings > Anomalies. Individual users can refine their notification preferences in My Profile > Notifications.
Comments
0 comments
Please sign in to leave a comment.