Statistical
Cost Anomaly
Updated Jul 28, 2026 · 1d ago
Catches whole-tenant log-volume spikes that translate into surprise observability bills — before the invoice does.
Example alert
Exact wording varies — the detector generates titles from the anomaly it finds. This is representative of what an alert looks like when it fires.
How it works
Where Volume Anomaly works per-service, this watches total tenant volume per hour-of-day against an EWMA-merged rolling baseline. When current volume exceeds the baseline ratio (default 3x) and an absolute floor, it fires with a top-services breakdown and, if a per-million-line cost is configured, a projected-bill impact. Checks every 10 minutes; baseline updates hourly.
Availability
Runs on these tiers:
Want to see this detector firing in the live demo?
Open alerts in the sandbox →Related detectors
- Volume Anomaly
Detects spikes, drops, and flatlines in log volume vs daily and weekly baselines per service.
- Silence Detection
Catches services that stop logging when they normally log every N seconds. The most dangerous failure mode: no errors, just absence.
- Outlier Detection
Multi-dimensional outliers in log feature space. Catches subtle anomalies that single-axis thresholds miss.
- Numeric Field Anomaly
Discovers the numeric fields your logs carry — payment amounts, cache hit rates, queue depths, inference scores — and flags when one drifts from its baseline.
- Post-Change Regression
Checks whether a deploy, config change or scale event actually made things worse, by comparing the window after the change against the matched window before it — per service.