Domain 1: Understand Usage & Cost
| Application | Visual One Intelligence (VisualOne / VSI) |
| Platform version referenced | v6.0.0.1 |
| FinOps Framework domain | Understand Usage & Cost |
| Capabilities in this section | Data Ingestion · Allocation · Reporting & Analytics · Anomaly Management |
| Source basis | VisualOne reference documentation (FinOps for VisualOne Reference Guide; VSI Screen Reference Guide; VSI Virtualization Reporting User Guide; Visual One Storage Reference) |
1.1 Data Ingestion
Capability: Collection, transfer, storage, and normalization of data from various sources, creating a complete, contextual dataset of technology usage and cost data available for analysis.
How VisualOne enables this
VisualOne ingests through an agentless collector model configured under Settings → Collection Devices, the configuration layer upstream of every report, it defines what infrastructure gets polled and when. Collection is performed by reading configuration files and instrumentation via CLI or REST API rather than by running workload-intensive agents, so collection is designed to avoid application performance impact on production systems. Typical initial setup is 1-2 hours including a data-collection setup call.
Supporting features
| Ingestion element | Implementation |
|---|---|
| Source breadth | 50+ registerable device/integration types spanning storage arrays, hyperconverged/virtualization platforms, backup software, and cloud/FinOps tooling, e.g. NETAPP_CLUSTER, PURE_DEVICE, THREE_PAR_DEVICE, V7000_DEVICE, IBM_FLASH_SYSTEM, DS8K_API_DEVICE, ISILON_DEVICE, HITACHI_HNAS_API_DEVICE, VPLEX_DEVICE, XTREMIO_DEVICE, COMPELLENT_DEVICE, VSAN_DEVICE, VMWARE_DEVICE, NUTANIX_DEVICE / NUTANIX_V4_DEVICE, SCALEIO_DEVICE, OPENSHIFT_DEVICE, VEEAM_BACKUP, COMMVAULT_BACKUP, COHESITY_BACKUP / COHESITY_HELIOS_DEVICE / COHESITY_HELIOS_SAAS_DEVICE, AVAMAR_DEVICE, DATA_DOMAIN_DEVICE, HP_STOREONCE_DEVICE, AMAZON_S3 |
| Non-infrastructure sources | CLOUDABILITY, RIGHT_SIZE, and FOLDER_WALKER_CONFIG collector types, third-party FinOps tool integrations and internal analysis jobs ingested through the same framework |
| Cloud ingestion | Azure resources ingested with full Azure Resource Manager resource ID paths, subscription-level sub-accounts, billing account identity, and per-resource raw tag JSON (observed across four production/DR subscriptions) |
| Per-source configuration | IP address / DNS entry name (required, inline-validated), device alias, username + password *or* SSH key auth, collection machine, collection day(s) (multi-select Mon-Sun), collection time (default 09:00), collection timeout (hrs), “Enable interval reporting?” flag |
| Transfer & scheduling controls | Global Auto Upload, Download Schedule, and Auto Update toggles; “Last VSI Client Session” check-in status line; an “Up Next” grid showing devices queued for their next scheduled collection run |
| Bulk onboarding | Bulk Import Devices (CSV-style bulk add), Update Selected bulk edit, per-row double-click edit |
| Storage / historization | The Collection Date model stores point-in-time snapshots; grids retain repeated snapshots per device across dates (the Amortization ledger holds 65 device-by-collection-date records, and effective-cost history is charted across a multi-year horizon) |
| Normalization, context | All ingested data is normalized into three analysis contexts, Storage, Compute/Virtual, and Cloud, plus a Total roll-up, applied consistently across every FinOps report |
| Normalization, metadata | Tag Key Mapping reconciles heterogeneous source tag vocabularies to a single internal standard (e.g. Unified BU ← BU, BusinessUnit, Dept, Department, CostCenter; Unified Environment ← environment, env, deploymentEnv, habitat; Unified Location ← datacenter, region, geography, site) |
| Normalization, units | Capacity normalized to GiB/TiB with effective vs. physical capacity handled explicitly; cost normalized to daily, monthly, and annual bases via documented conversion factors (monthly ÷ 30.42 → daily; daily × 365 → annual) |
| Normalization, open standard | FOCUS Export presents the normalized dataset in FinOps Open Cost and Usage Specification format (285 records observed), with FOCUS-aligned fields: Charge Period Start/End, Resource ID, Resource Name, Resource Type, Service Category, Service Name, Charge Category, Effective Cost, Billing Account ID/Name/Type, Sub Account ID/Name/Type, plus Tags and Allocated Tags, downloadable as JSON |
| Collection cadence | Scheduled by day-of-week and time per device; reports are updated daily or weekly based on collection cycles, with more frequent updates configurable to requirements |
| Completeness safeguards | “Complete and Accurate Data” is a named success factor: all devices registered, cost parameters current, tags consistently applied, regular validation and reconciliation |
Personas served
FinOps Practitioner (dataset completeness, FOCUS interchange), Engineering (collector registration, credential and schedule management), Finance (auditable point-in-time snapshots).
1.2 Allocation
Capability: Assigning and sharing technology costs using accounts, tags, labels, and other metadata, creating accountability among teams and projects.
How VisualOne enables this
Allocation is built on a defined chain: Infrastructure Device → Tags Applied → Tag Key-Value Pairs → Tag Summary Report → Chargeback Report → Department/Business Unit Allocation. Tags are the mechanism that links technical resources to organizational structure, and a single device can carry multiple tags, enabling simultaneous multi-dimensional allocation (e.g. BU + Environment + Cost Center on the same array).
Supporting features
| Allocation element | Implementation |
|---|---|
| Metadata capture, storage | Storage Device Tagging maintains Array Name, Vendor, Data Center, Operational Category, Purchase/Retired Date, Classification, Device Type Category, Maintenance Cost, Purchase Price |
| Metadata capture, compute | ESX Host Tagging maintains Host Name, Cluster Name, vCenter Name, Purchase Price, Purchase/Retiring Date, Annual Maintenance, Total Cores, Total Memory (GiB), Model, Serial Number |
| Tag catalog | All Tags Report, master directory of every distinct tag key/value discovered (73 records observed), columns Tag Key / Tag Value / concatenated Tag, with double-click drill-through into per-tag detail |
| Tag portfolio scale | Tag Cost Inventory reports 56 tags analyzed under 28 tag keys, with observed keys including BU, Operational Category, Owner, Company, Function, Cluster Tag, Custom Tag, Kubernetes, Description, plus cloud-native keys (creation_time, databricks-environment, defaultExperience, deploymentHash, ms-resource-usage) |
| Cost by tag | Tag Summary returns daily cost for a selected Tag Key/Tag Value split across Storage, Cloud, and Virtual panels, each with its own record count and resource-level detail table (Storage: Host Name / LUN Name / Daily Cost; Cloud: Resource Name / Service Type / Daily Cost; Virtual: VM Name / Cluster / Daily Cost) |
| Tag spend visualization | Tag Cost Inventory provides a Monthly Costs by Tags treemap, a Top 10 Spender Tags trend multi-line chart, and KPI tiles for Total Infrastructure Spend, Tags Analyzed, Average Cost Per Tag, and Top Spender |
| Organizational allocation | Chargeback Report with a selectable grouping dimension (default Department) and a selectable cost metric (default Total Cost), rendered as a horizontal stacked bar by cost center with per-resource segments; grid holds one record per department × resource × period (thousands of records) |
| Allocation methods | Three models: equal split (Total Cost ÷ number of units), usage-based (Total Cost × Department Usage ÷ Total Usage), and tag-based (sum of all resource costs carrying the department tag). Allocation model is administrator-configurable |
| Sub-resource allocation | Compute cost is split by a configurable percentage model, Memory Cost % and CPU Cost % (typical 50/50), enabling per-vCPU and per-GiB-memory chargeback of a shared host |
| Shared / split cost support | FOCUS Export exposes Allocated Method ID, Allocated Resource ID, Allocated Method Details, Allocated Resource Name, and Allocated Tags, supporting allocation/splitting rules that distribute shared cost across multiple consumers |
| External system alignment | Foreign Tag Key mapping allows internal allocation dimensions to reconcile to cloud provider tag schemas, external billing systems, ITSM platforms, and custom organizational systems |
| Untagged visibility | An explicit Unknown value is carried under the BU tag key, surfacing unallocated spend rather than silently dropping it |
| Tag coverage management | Consistent tag application is a named success factor, supported by the documented tag governance workflow: review All Tags for standardization, verify required tags are applied, check name consistency, validate external mapping, and correct non-compliant tags |
Personas served
FinOps Practitioner (allocation model design and tag hygiene), Finance (cost center accountability), Engineering (tag application at the resource level), Leadership (departmental accountability reporting).
1.3 Reporting & Analytics
Capability: Analysis of technology data to create reports that yield insight into usage and spend patterns, identify improvement opportunities, and support informed decision-making.
How VisualOne enables this
Reporting is the core of the platform. The FinOps menu alone contains 14 purpose-built reports, sitting alongside Executive Reports, a 23-screen Storage module, and a full Virtualization Reporting module, all built on a single, consistent analytical grid and charting framework so interaction patterns transfer between screens.
Report inventory (FinOps menu)
| Report | Analytical purpose |
|---|---|
| Tag Cost Inventory | Current-month spend by tag with treemap, top-spender trending, and inventory drill-down |
| Tag Summary | Per-tag cost across Storage / Cloud / Virtual with daily average cost trend |
| Tag Forecasting (Tag Capacity Planning) | Forward-looking cost projection by tag |
| Tag Cost Modeling | What-if workload cost modeling |
| Savings Report | Estimated savings opportunity by context |
| Chargeback Report | Cost allocation to organizational dimensions |
| Amortization Report | Asset depreciation value over time (monthly) |
| All Tags Report | Master tag key/value catalog with drill-through |
| Cost YTD Report | Year-to-date cost by context with month-over-month trend |
| Cost Per Sector Report | Budget vs. actual and variance by sector |
| Financial Administration Report | Full asset financial ledger (capital, operating, normalized) |
| Optimization Recommendations | Actionable recommendations with savings and status |
| Cost Efficiency Dashboard | 0-100 asset efficiency scoring, scorecard and matrix views |
| FOCUS Export | Standards-based cost/usage dataset export |
Analytical framework
| Capability | Implementation |
|---|---|
| Grid analytics | Every data table shares an AG Grid-style component: search/filter, saved-view selector, drag-to-group row grouping, Pivot Mode, a Columns side panel for visibility and aggregation selection (sum / avg / max), and export controls |
| Time analysis | Zoom presets (1m, 3m, 6m, YTD, 1y, All), Save view, explicit start/end date pickers, and a brush/range-selector slider beneath trend charts |
| Snapshot control | Global Collection Date picker allows any report to be run against a prior data snapshot for point-in-time comparison, post-change validation, and audit-period alignment |
| Context switching | Tab-style context switchers (Total / Storage / Compute / Cloud; Storage / Compute; Context / Tag Key; Scorecard / Matrix) re-render every chart and grid on the page simultaneously |
| Visualization variety | Bar, horizontal stacked bar, grouped bar, donut/pie, treemap, multi-line time series, dual-axis performance charts, gauge/dial, and tiered matrix cards |
| Drill-down paths | All Tags → (double-click) → Tag Summary → “To Capacity Planning” → Tag Forecasting; Health Alerts → related cluster/host/datastore/VM screen; Device Summary → Device Details |
| Change analysis | Enterprise Delta Report and Virtual Delta Report compare two points in time at a selectable increment (e.g. 1 month), quantifying Used Growth (GiB), % Used Growth, IOPS End, Latency Change, and SPM Growth by device type |
| Efficiency analytics | Cost Efficiency Dashboard scores each asset 0-100 on cost-to-capacity/performance and classifies into Optimal / Efficient / Underutilized / Wasteful, with Overall Efficiency gauge, Top Performers, and Low Value panels |
| Saved and shared views | Named saved views per grid and saved chart zoom ranges make analyses reproducible and shareable across the team |
| Distribution & exports | Custom Email / Generate Report control in the global header for building and distributing reports by email; weekly efficiency reports can be delivered by email; grids export, and FOCUS data exports as JSON |
| Empty-state handling | Filtering to a combination with no data returns “No Rows To Show” and $0.00 rather than erroring |
Personas served
All core personas. Engineering and FinOps Practitioners work in the detail grids and drill-downs; Finance uses the Financial Administration, Amortization, Chargeback, and Cost Per Sector reports; Leadership consumes Executive Reports, the Cost YTD roll-up, and the Cost Efficiency gauge.
1.4 Anomaly Management
Capability: Detect, identify, alert on, and manage unexpected or unforecasted cost and usage irregularities in a timely manner.
How VisualOne enables this
VisualOne combines two complementary mechanisms: a production alerting and acknowledgement system for infrastructure health and configuration irregularities, and analytical detection surfaces for cost and usage irregularities.
A. Alerting and alert lifecycle management
| Element | Implementation |
|---|---|
| Enterprise Health Alerts | Dedicated screen (/reports/storage/enterprise-alerts) holding 533 unacknowledged alert records in the observed environment |
| Severity model | Two-level severity for storage (Warning non-critical, Alert critical); three-level for virtual (critical / warning / info), each with a severity filter |
| Alert record schema | ID, Context, Collection Date, Severity, Device Name, Display Name, Category, Alert type, Description, Acknowledged?, ServiceNow |
| Alert categories observed | Storage Layout, Hard Quota Applications, Advisory Quota issues, Configuration issues |
| Lifecycle management | Acknowledge (hide) workflow with an Acknowledged filter (All / Yes / No); bulk acknowledgement via Shift+Click, up to 10 rows per action, producing an auditable acknowledged/unacknowledged state per alert |
| Escalation | Per-row ServiceNow dropdown creates or links an incident ticket directly from the alert, moving irregularities into the enterprise incident management workflow |
| Device-scoped view | Device Health screen carries a per-device alert inventory (211 records observed) with severity categorization and alert distribution breakdown |
| Status indicator layer | Six always-on Green/Yellow/Red indicators per device, Configuration & Setup, Balance, Server Volume Mapping, Errors & Other Alerts, Storage Layout, Volumes & Snapshots, with Enterprise Health Report aggregating them across the estate |
| Triage workflow | Daily workflow: filter to Critical + unacknowledged → pivot to the affected unit via device + target → root cause → remediate → bulk acknowledge after validation |
B. Cost and usage irregularity detection
| Element | Implementation |
|---|---|
| Trend-based spike detection | Cost YTD month-over-month multi-line chart supports anomaly detection of unusual cost spikes and visual trend analysis; Tag Summary’s daily average cost trend supports identifying cost spikes or anomalies at the tag level |
| Variance-based detection | Cost Per Sector produces Variance $ and Variance % per sector; the governance workflow investigates variances >10% and tracks a variance trend month over month (e.g. −5% → 0% → +5% → +10% flagged as an increasing over-budget trend requiring investigation) |
| Period-over-period delta detection | Delta Report quantifies change between two dates at a chosen increment, surfacing outsized capacity and performance swings by device type (observed deltas ranging from −640,348 to +33,544) |
| Waste/outlier detection | Cost Efficiency Dashboard tiers every asset and isolates the Low Value / Wasteful outliers; Savings Report and Orphaned VMDK inventories surface unexpected orphaned resources |
| Forecast deviation | Forecast lines plotted alongside actuals on the same axis allow actual-vs-projected divergence to be read directly |
| Investigation path | Detected irregularities are traced through the drill-down chain, tag → resource → device, to isolate the contributing resource |
Personas served
Engineering and Operations (daily alert triage, ServiceNow escalation), FinOps Practitioner (variance and trend investigation), Finance (budget variance escalation).
Section summary
| Capability | Primary supporting surfaces |
|---|---|
| Data Ingestion | Collection Devices (50+ types, agentless), Tag Key Mapping, context normalization, FOCUS Export |
| Allocation | Tagging system, All Tags, Tag Summary, Chargeback, three allocation models, FOCUS Allocated* fields |
| Reporting & Analytics | 14 FinOps reports plus Storage and Virtual modules, pivot-capable grid framework, drill-down paths, saved views, email distribution |
| Anomaly Management | Enterprise and Virtual Health Alerts with acknowledgement and ServiceNow escalation; cost detection via trend, variance, and delta reporting |