Skip to content

Anomaly Detection

Anomaly Detection uses machine learning to identify unexpected changes in cloud spend, alert your team, and surface the signals needed to investigate root cause.

When to use it

  • A cost spike appeared in Cost Explorer and you need to understand why.
  • You want proactive alerts when a service or team's spend deviates from expected.
  • You want to monitor spend within specific business boundaries (a team, environment, or product).

Open Anomaly Detection

Go to Cost Management > Anomaly Management from product navigation.

Tabs

Tab What it shows
Detected Observed, ML-detected spend anomalies across connected providers
Perspectives Anomalies within user-defined business scopes (teams, products, environments)
Predicted Forecasted anomalies — spend predicted to exceed expected ranges
Custom Rules User-defined alert rules with custom thresholds and severity

Some tenants may see Anomalies & Forecasts as a combined view.

Investigate an anomaly

  1. Open the relevant tab.
  2. Apply date or scope filters.
  3. Select an anomaly to open its detail view.
  4. Review the time window, affected service, cost delta, and contributing signals.
  5. Click through to Cost Explorer using the same date, provider, account, and service to verify and dig deeper.
  6. Check for billing corrections, late credits, or refunds before escalating.

Set up custom alert rules

  1. Open the Custom Rules tab.
  2. Create a rule with a spend threshold, scope, severity, and notification frequency.
  3. Configure recipients in Settings > Notification Settings.

Using Perspectives for team-level anomaly monitoring

Create a Perspective for each team or product, then use the Perspectives tab to monitor spend anomalies within each business boundary. This gives team leads visibility into their own cost signals without requiring access to org-wide data.

Best practices

  • Validate late credits and billing corrections before escalating a detected anomaly.
  • Set custom rule thresholds conservatively — thresholds that are too narrow create alert noise.
  • Record the exact time window and cost type when sharing anomaly findings.
  • Use the Predicted tab proactively — catching a predicted anomaly before month-end is easier than explaining a bill after.

Troubleshooting

If no anomalies appear when you expect them, see Missing recommendations and anomalies.