Skip to content

Changelog

Release history for AI Monitor — ML-powered anomaly detection for CloudWatch metrics.

26h4

  • Detection and alerting refinements
  • Web application security hardening

26h3

  • Scheduled maintenance release
  • Update AWS Metric Namespace Catalog
  • AWS Qualified Software

26h2 (Sep 2026)

  • MoM enhancements
  • Move timezone selection to FAQ
  • Now maintain local changes with Save, Undo and Diff
  • Added support link to landing and fulfillment pages
  • Change logout behavior
  • Add AI SIEM checkbox for future integration with the AI SIEM product

26h2 (Aug 2026)

  • On stack update, address the "Could not locate index-pattern-field" errors on dashboard visualizations requiring a manual index refresh
  • AWS FTR Approved

26h2 (July 2026)

  • Support for AWS Organizations — consolidate and centrally govern multiple AWS accounts
  • Enhanced Correlation — now leverages specific Log Processor patterns when anomalies occur
  • iPad layout fix — subscription list footer buttons now display correctly on tablet viewports
  • Preview-based cloning — create new alerts based on wildcard search
  • Popout panels — Baseline and Graph can now be popped out to a larger window
  • Threshold enhancements — improved AI support for hard high/low threshold alerts
  • FAQ — now includes alert recipient state, entitlement state, and Bedrock endpoint availability
  • AI Tune v2 — tuning recommendations are now computed deterministically using rules-based logic (anomaly frequency, metric type, observed percentiles) rather than relying solely on the language model for numeric decisions. Bedrock is still used to generate the human-readable explanation, but threshold values, direction, and static alert recommendations are derived from your actual data and SLA-appropriate defaults.

26h1 (June 2026) — Initial Release

Anomaly Detection

  • Random Cut Forest (RCF) scoring with per-day-of-week adaptive baselines
  • Z-score anomaly scoring (0–10 scale) with configurable thresholds per subscription
  • Direction filtering: alert on high-only, low-only, or both deviations
  • Static threshold alerts (Alert if below / Alert if above) for absolute floor/ceiling safety nets
  • Wildcard dimension support with per-resource independent scoring
  • Wildcard batching optimization for high-dimension-count subscriptions (compact+ tiers)
  • Anomaly trend tracking: worsening, improving, stable, new
  • Configurable anomaly retention (per-subscription override on advanced+)

AI-Powered Features

  • Natural language metric discovery via Amazon Bedrock (Claude Haiku)
  • AI tuning suggestions based on anomaly history with Ctrl+click OpenSearch full-history mode
  • AI-generated anomaly explanations (async batch with circuit breaker and 7-day cache)
  • AI executive summary in weekly anomaly reports
  • Smart defaults from AWS metrics catalog (auto-fill stat, direction, threshold, period)
  • Next/Prev navigation for multiple AI suggestions with duplicate detection

Metric Discovery

  • Discovery wizard with namespace/metric browser
  • Quick-subscribe chips with pre-configured smart mappings (no AI call)
  • AWS/TrustedAdvisor integration (RedFlagChecks, YellowFlagChecks, ServiceLimitUsage)
  • AWS metrics catalog with 57+ namespaces, auto-updated via Bedrock
  • Show-all-AWS-metrics toggle (active + catalog inactive)
  • Double-click to subscribe from discovery list
  • Return to expanded namespace after save/cancel

Subscription Editor

  • Browser-based editor with split-panel layout and keyboard navigation
  • Preview metric data (Shift+click = 24h, Ctrl+click = OpenSearch cross-account)
  • Learned baseline visualization with per-day-of-week sparklines
  • Version history with JSON diff and one-click rollback
  • Clone, enable/disable all, double-click toggle
  • Deep-link support (?sub=id) for anomaly email links
  • Session expiry detection with 60-second keepalive ping
  • Timezone selector with local time display throughout

Anomaly Management

  • Recent anomalies panel with subscription and score filtering
  • Anomaly detail view with CloudWatch console link, trend info, AI analysis
  • Dismiss single, dismiss all for subscription (Shift+click skips confirmation)
  • Orphan detection: deleted subscriptions shown as "(deleted)" in anomaly detail
  • Red badge count on Anomalies toolbar button

Alerting & Reports

  • SNS alerts with severity, trend, training status, CloudWatch link, and runbook URL
  • Configurable email notifications with per-subscription notify threshold
  • Cost context in billing anomaly alerts (today vs baseline, % change)
  • Weekly anomaly report with AI executive summary, severity breakdown, cost analysis, system health
  • Report scheduling (per day-of-week) with configurable lookback window
  • On-demand report generation with auto-select in preview
  • Editor deep-link in alert emails

Maintenance & Suppression

  • Scheduled and ad-hoc maintenance windows (compact+ tiers)
  • Per-subscription or global suppression with start/end SNS notifications
  • Suppression metrics and reporting

Correlation

  • Cross-metric correlation engine (compact+ tiers)
  • Configurable correlation window (1–30 minutes) per subscription
  • Correlated metrics included in anomaly alerts

Cross-Account

  • Multi-account metric ingestion via Metric Stream + Firehose + cross-account S3
  • Per-subscription account filtering (local, specific, all)
  • Cross-account anomaly tracking and reporting
  • Setup script for remote account configuration

Cost Monitoring

  • Billing processor Lambda for daily cost aggregation by service
  • Cost anomaly detection (spending spikes vs day-of-week baseline)
  • Cost trends in weekly reports with 7-day average comparison

OpenSearch Integration

  • Automatic dashboard import (7 dashboards, 20+ visualizations)
  • Anomaly events indexed to OpenSearch for dashboard visibility
  • Metric Explorer dashboard for ad-hoc investigation
  • Re-import on every stack deploy via custom resource

Operations

  • CloudWatch dashboard with detector duration, anomaly counts, AI metrics, system health
  • CycleDuration EMF metric for detector performance monitoring
  • Support bundle script for diagnostics collection
  • SSO integration (SAML/OIDC) for enterprise tier
  • RBAC: admin and viewer roles via Cognito groups
  • Landing page with stack info, editor link, dashboards link
  • Custom domain setup script
  • Service quota check script

Tiers

  • Five tiers: Basic, Essential, Compact, Advanced, Enterprise
  • Per-Lambda memory, timeout, and concurrency configuration
  • Marketplace entitlement integration with dynamic feature gating
  • Entitlement-aware processing with grace period on expiry