Anomalies
See what's running hot right now, fix the biggest first, and route each anomaly to an owner.
Monitor → Anomalies shows every place spend left its expected pattern, what it's costing per day, and who owns it. The header shows when the detector last ran, such as Detector ran Sep 25, 19:19.
State right now
The top panel answers how bad is it?
- A status such as Needs attention.
- The excess per day from running anomalies, such as +$1.1K/day excess from 17 running anomalies.
- The count by severity and how many are unowned.
- A chart of excess cost over the date range, stacked by severity (High, Medium, Low).
Fix these first
The side panel ranks the top five running anomalies by their share of the burn rate.
| Field | Meaning |
|---|---|
| Burn rate | Total excess per day across running anomalies |
| No owner | How many running anomalies have no owner, and their excess per day |
| Ranked list | Service, type, ID, share of burn, start date, and excess per day |
Select Assign to me to take one.
Anomaly types
| Type | Meaning | Example |
|---|---|---|
| New spend | A cost that didn't exist before | Claude Sonnet 4.6 (Amazon Bedrock Edition) · new, was $0 |
| Spike | A short jump above the expected level | EC2 Container Registry · $8 → $66 |
| Step up | A lasting move to a higher level | EC2 - Instances · $156 → $262 |
| Recurring | A spike that repeats on a schedule. Shown with its cadence, such as Recurring · fortnightly · 3×. | Month-start licence charges |
Severity
Each anomaly is rated High, Medium, or Low from its impact per day and how far it left the expected range. Auto-create rules can open tickets by severity. See Detection rules.
The anomaly table
Tabs: Active (running now, with total excess per day), Ended, All, and False positive.
Quick filter chips narrow the table by severity (High, Medium, Low), assignment (Unassigned, Assigned), and category (Data & AI, Compute, Network, Storage).
| Column | Meaning |
|---|---|
| Anomaly | Service, type, ID, category, and the usage type behind it, such as USE1_InputTokenCount-Units |
| Account | Where it's happening |
| Running | How long, and since when |
| Status | Open, and so on |
| Owner | The owner, or Unassigned |
| Impact / day | Excess per day and the before → after level |
| Last 3 weeks | Sparkline |
Row actions
| Action | What it does |
|---|---|
| Assign | Choose an owner |
| + Ticket | Open a ticket |
| ✦ | Investigate in Iris |
Scope, dates, and export
At the top right: the date range (a preset or Custom), Scope (All clouds or one provider), and Export.
Mark a false positive
When an anomaly is expected (a planned migration, a load test), mark it as a false positive. It moves to the False positive tab and stops counting toward the burn rate.
Investigate an anomaly
See Investigate a cost spike for a step-by-step walkthrough.