Skip to main content

Access anomalies

Required permissions

  • Anomalies Viewer: To view cost anomalies.
  • Anomalies Manager: Additionally required to acknowledge, resolve, and comment.
  • Allocations Admin, Cloud Analytics User: For anomaly detection on custom allocations.

View the anomaly list

To view the list of detected cost anomalies, sign in to the DoiT console, select Policy and governance from the top navigation mega menu, and then select Cost anomalies.

The cost anomalies list page.

On the Cost anomalies page, you can:

  • Change the Time range or use anomaly properties to filter the results. (DoiT platform stores all the historical cost anomalies.)

  • Select Anomaly settings to adjust the sensitivity settings and manage notifications.

  • Select Export to CSV to export the list of cost anomalies for custom analysis and reporting outside the DoiT console. The CSV file includes all supported properties (except thumbnail images) and preserves the sorting and filtering applied to the list.

  • For each anomaly, you can review its properties, or select the View button in the Details column to view its details.

Anomaly properties

Each anomaly entry on the Cost anomalies page provides the following information (you can select the Edit icon to choose which columns to show or hide, or reorder them):

  • Start Time: The beginning of the usage window when the aggregated cost exceeds the predefined threshold and is considered a potential anomaly.

    • For anomalies based on billing data, this field shows the start date (billing data time series use a daily interval, with each day starting at 00:00 UTC).

    • For anomalies based on real-time usage data, this field shows the start hour in your local time zone, based on your browser setting (real-time usage data time series use an hourly interval).

  • Status: Shows whether the anomaly is Active or Inactive. See Dynamic updates for more information.

  • Review status: Shows where the anomaly is at in your team's investigation cycle: Needs review, Under review, Resolved · Anomaly confirmed, or Resolved · Not an anomaly. See Review and classify anomalies for more information.

  • Project/Account: See Standard dimensions: Project/Account ID. For service-level anomalies, this field shows the project or account ID when one resource is responsible, a provider-specific count when multiple contribute (for example, "3 projects" or "3 accounts"), or an em dash when no information is available.

  • Service: See Resource metadata: Service.

  • SKU: Stock Keeping Unit of a service, see Resource metadata: SKU. For service-level anomalies, this field shows the SKU name when one SKU is responsible, the number of contributing SKUs (for example, "3 SKUs") when multiple SKUs contribute, or an em dash when no SKU information is available. Near real-time anomalies are detected at the service level only.

  • Severity: The severity level of the anomaly: Information, Warning, or Critical. DoiT defines the three severity levels in accordance with the extent to which the actual cost deviates from the established pattern.

  • Excess cost: The difference between the actual cost and the upper bound of the normal range.

  • Anomaly: A thumbnail image of the anomaly chart.

Anomaly sensitivity settings

When evaluating whether a spend qualifies as an anomaly, one criterion is whether the spend exceeds the established normal range. The broader the range, the fewer anomalies will be identified.

To adjust the normal range, you can modify the anomaly sensitivity settings:

  1. From the Anomaly settings dropdown, select Anomaly sensitivity settings.

  2. In the Anomaly sensitivity settings dialog, review the current sensitivity settings and the audit log of the latest update, if applicable.

    Anomaly sensitivity setting

  3. Update the global sensitivity setting, or add, modify, or remove the sensitivity scale of individual services.

    Sensitivity settings configured at the service level always override the global setting.

  4. Save your changes.

    The new sensitivity settings only affect evaluations performed after the change; they do not affect anomalies already identified.