AWS Cost Anomaly Detection

AWS cost anomaly detection that judges every service against itself

Xplorr reads your daily AWS cost with read only credentials and compares each service, in each account and region, with its own average over the previous seven days. When a day runs well above that line, the alert lands in Slack and email with the actual and baseline cost side by side. The same detection covers Azure and GCP if you connect them.

Xplorr alerts page in the demo workspace showing open anomalies, the excess spend above baseline, and a table of detected anomalies with account, service, region, actual and baseline cost, spike percentage, severity and status.

Inputs

Where the AWS anomaly numbers come from

Xplorr reads your accounts with read only credentials and never writes to your infrastructure. These are the sources behind this screen.

Daily AWS cost by service, account and region
Read from the Cost Explorer API (GetCostAndUsage) with an IAM user or an assumed role limited to read actions. Detection runs on billed cost, so every alert corresponds to money. AWS permissions
The recent history of that same series
The baseline for EC2 in one account and region is built from EC2 in that account and region, so a service that costs a few dollars a day is never judged against one that costs thousands.
CloudTrail events, for root cause
Evidence based root cause reads CloudTrail LookupEvents around the day of the spike. It is rolling out to selected organizations and is not generally available yet.

Method

How the AWS anomaly numbers are worked out

No black box. If a figure is an estimate or an apportionment rather than a billed line, the page says so.

  1. A baseline per service, account and region

    Each day is compared with the average of the previous seven days for the same series. There is no single threshold for the whole bill to tune.

  2. A spike has to be large and worth money

    A day must run more than 50% above its baseline to count, and a change of a few cents on a service that costs under a dollar a day is ignored, so small services do not flood the queue.

  3. Severity follows the size of the jump

    An increase of 50% is graded low, a doubling medium, a tripling high and a sixfold jump critical, so a wobble and a runaway do not arrive looking the same.

  4. The alert goes where people read

    New anomalies are posted to your connected Slack workspace and emailed to the organization admins, each of whom can turn anomaly emails off in their own notification settings. A signed anomaly.created webhook is available for other tools.

  5. Every anomaly has a status

    Mark one as expected, optionally muting that series for up to 90 days, take it as investigating, or resolve it, so the open list only holds what still needs a look.

In the console

What is on the AWS anomaly screen

  • Open anomalies, with the critical ones counted separately
  • Total spend above baseline across everything still open
  • Account, service and region for each anomaly
  • Actual cost against baseline cost, with the spike as a percentage
  • A short AI summary written from the last 14 days of that series
  • Expected, investigating and resolve actions on each row

Common questions about AWS anomaly

How is this different from AWS Cost Anomaly Detection?
AWS Cost Anomaly Detection is free, uses machine learning models run by AWS, and sends its alerts by email or SNS. It only sees AWS. Xplorr does not read the anomalies AWS finds; it runs its own detection on the Cost Explorer data it already syncs, applies the same method to Azure and GCP, and sends the result to Slack and email with the baseline attached. Many teams keep both.
How quickly does an anomaly show up?
It follows your billing data, which AWS publishes with a delay of up to a day. That makes this a next day signal rather than a real time one, which is still weeks earlier than the invoice.
Does it tell me what caused the spike?
Each anomaly gets a short AI summary written from the recent cost history of that series. An evidence based root cause, which reads CloudTrail events around the spike and names the actor, action and resource it considers most likely, is rolling out to selected organizations and is not generally available yet.
What access does Xplorr need in my AWS account?
Read only access to Cost Explorer and a few describe and metric actions. The documentation lists the full least privilege policy. Xplorr never writes to your account, and it does not need permission to create or change anomaly monitors.
What does it cost?
Xplorr is free during the private beta, with every feature available. Plans and their published prices are on the pricing page.

Background reading

What counts as an anomaly, and what a runaway Lambda or an accidental cross region transfer looks like in the data, is covered in What is a cloud cost anomaly.

To set up the native AWS service alongside budgets and forecasted alerts, follow the cloud cost monitoring and alerting guide.

How this compares

See this on your own accounts

Connect a cloud account with read only credentials and the first sync pulls your last 30 days, so this screen fills with your numbers instead of the demo workspace. Free during beta.