epok

Statistical

Cost Anomaly

Updated Jul 28, 2026 · 1d ago

Catches whole-tenant log-volume spikes that translate into surprise observability bills — before the invoice does.

Example alert

tenant log volume 11x typical for this hour (top driver: debug-worker) — projected +$420 today

Exact wording varies — the detector generates titles from the anomaly it finds. This is representative of what an alert looks like when it fires.

How it works

Where Volume Anomaly works per-service, this watches total tenant volume per hour-of-day against an EWMA-merged rolling baseline. When current volume exceeds the baseline ratio (default 3x) and an absolute floor, it fires with a top-services breakdown and, if a per-million-line cost is configured, a projected-bill impact. Checks every 10 minutes; baseline updates hourly.

Availability

Runs on these tiers:

TrialTeamGrowthCustom

Want to see this detector firing in the live demo?

Open alerts in the sandbox →

Related detectors

  • Volume Anomaly

    Detects spikes, drops, and flatlines in log volume vs daily and weekly baselines per service.

  • Silence Detection

    Catches services that stop logging when they normally log every N seconds. The most dangerous failure mode: no errors, just absence.

  • Outlier Detection

    Multi-dimensional outliers in log feature space. Catches subtle anomalies that single-axis thresholds miss.

  • Numeric Field Anomaly

    Discovers the numeric fields your logs carry — payment amounts, cache hit rates, queue depths, inference scores — and flags when one drifts from its baseline.

  • Post-Change Regression

    Checks whether a deploy, config change or scale event actually made things worse, by comparing the window after the change against the matched window before it — per service.

← All detectors