olOpsLyft Docs

Anomalies

See what's running hot right now, fix the biggest first, and route each anomaly to an owner.

Monitor → Anomalies shows every place spend left its expected pattern, what it's costing per day, and who owns it. The header shows when the detector last ran, such as Detector ran Sep 25, 19:19.

State right now

The top panel answers how bad is it?

  • A status such as Needs attention.
  • The excess per day from running anomalies, such as +$1.1K/day excess from 17 running anomalies.
  • The count by severity and how many are unowned.
  • A chart of excess cost over the date range, stacked by severity (High, Medium, Low).

Fix these first

The side panel ranks the top five running anomalies by their share of the burn rate.

FieldMeaning
Burn rateTotal excess per day across running anomalies
No ownerHow many running anomalies have no owner, and their excess per day
Ranked listService, type, ID, share of burn, start date, and excess per day

Select Assign to me to take one.

Anomaly types

TypeMeaningExample
New spendA cost that didn't exist beforeClaude Sonnet 4.6 (Amazon Bedrock Edition) · new, was $0
SpikeA short jump above the expected levelEC2 Container Registry · $8 → $66
Step upA lasting move to a higher levelEC2 - Instances · $156 → $262
RecurringA spike that repeats on a schedule. Shown with its cadence, such as Recurring · fortnightly · 3×.Month-start licence charges

Severity

Each anomaly is rated High, Medium, or Low from its impact per day and how far it left the expected range. Auto-create rules can open tickets by severity. See Detection rules.

The anomaly table

Tabs: Active (running now, with total excess per day), Ended, All, and False positive.

Quick filter chips narrow the table by severity (High, Medium, Low), assignment (Unassigned, Assigned), and category (Data & AI, Compute, Network, Storage).

ColumnMeaning
AnomalyService, type, ID, category, and the usage type behind it, such as USE1_InputTokenCount-Units
AccountWhere it's happening
RunningHow long, and since when
StatusOpen, and so on
OwnerThe owner, or Unassigned
Impact / dayExcess per day and the before → after level
Last 3 weeksSparkline

Row actions

ActionWhat it does
AssignChoose an owner
+ TicketOpen a ticket
✦Investigate in Iris

Scope, dates, and export

At the top right: the date range (a preset or Custom), Scope (All clouds or one provider), and Export.

Mark a false positive

When an anomaly is expected (a planned migration, a load test), mark it as a false positive. It moves to the False positive tab and stops counting toward the burn rate.

Investigate an anomaly

See Investigate a cost spike for a step-by-step walkthrough.

On this page