Skip to content

Cost Anomaly Detection

A daily billing processor computes day-over-day spend deltas per AWS service and detects unusual cost spikes using day-of-week baselines — for example, "RDS costs 3x more than a normal Thursday."

Cost anomaly detection is available on the compact tier and above.

How it works

The billing processor queries AWS/Billing EstimatedCharges data from OpenSearch, computes the day-over-day spend delta per service, and writes derived DailySpend metrics back. The detector then scores these like any other metric using day-of-week baselines, so it learns that "Tuesdays cost more than Sundays" and only alerts on genuine cost spikes — not normal weekly patterns.

Subscribe to AIMonitor/Billing / DailySpend with {"ServiceName": ".*"} to monitor all services independently. Cost context (today vs baseline, % change) is included in billing anomaly alerts and in reports with a 7-day average comparison.

Multiple accounts

If cross-account metric streams include AWS/Billing from linked accounts, the processor computes per-account per-service deltas and alerts include the account ID. Note: AWS/Billing metrics only exist in the payer (management) account unless billing access is delegated to member accounts.