Disclosed are techniques for determining possible causes of anomalous state in computing nodes. A computing node is analyzed for a given time period against another computing node over another time period. Individual metrics such as network bandwidth are measured and a subset of these metrics that are determined to be most likely related to the cause of anomalous state are provided to a user.