Anomalies
Anomalies Detection Overview
Finout's advanced algorithms analyze historical data to pinpoint cost anomalies within your MegaBill. Finout identifies both cost increases and decreases, allowing you to quickly investigate the reason for any deviations from your regular spending. In addition, you can monitor these anomalies within Finout or receive anomaly updates directly via Slack, MS Teams, ServiceNow (coming soon), or email.
For comprehensive tracking, Finout scans your most frequently used tags, services, cost centers, and virtual tags. Each newly created virtual tag includes an anomaly scan to ensure you get a holistic view of your data.
Anomaly types:
Predefined Anomalies: These are anomalies identified by Finout for significant cost groups and filters. You have the option to modify these to better fit your specific requirements.
Custom Anomalies: Customize your cloud cost anomaly detection to meet your team's unique needs. You can set your own rules, thresholds, and patterns to align with your specific cost management strategies. Custom anomalies offer the flexibility to pinpoint and tackle cost inconsistencies that are most pertinent to your team.

There are four main functions in Anomalies:
Anomalies Feed
In the Anomalies Feed, you can see all of your anomalies and filter, investigate, and manage them.
Anomaly data is retained for 3 months. Anomalies older than that are automatically removed from the feed and won't be accessible.

Filters:
Time Frame - The default is the last 30 days. You can either select one of the predefined options or switch to custom.
- When switching to custom, you can define a custom start and end date. You can keep Today as the relative end date or unmark it to set a custom end date.

Anomaly threshold: Filter anomalies based on specific thresholds. Threshold is changing based on the selected anomaly type. For example: Set a threshold of over 20% will display all anomalies exceeding this limit.

Type: Select the anomaly type.
Cost center: Select a cost center.
Key: Select a Key.
Value: Select a value.
Search: Use free text search to find anomalies based on various terms or descriptions.
Create Anomaly Alert: To create an Anomaly Alert, see Create Custom Anomalies.
Anomaly Settings:
In the Anomalies Feed, click
and then click Anomalies Settings. The Anomalies Settings pop-up appears.

Choose a default endpoint.

Choose the maximum number of alerts per day.

Limitations:
The threshold applies only to anomaly alerts; FP alerts and reports are unaffected.
Cost, Usage, and Unit Economics have a combined maximum of 150 per day, prioritized by highest anomaly value.
Run Rate alerts have a separate maximum of 100 per day, prioritized by the highest budget anomaly value.
Commitment Expiration alerts have a separate maximum of 150 alerts per day, prioritized by closest expiration date.
Anomaly data is retained for 3 months. Anomalies older than that are automatically removed from the feed.
Anomaly creation for new Virtual Tags: By default, Finout creates anomalies for each newly created virtual tag.

Click Save.
Clear Anomalies Feed:
Important: Proceed with caution, this action will clear the whole anomalies feed. Clearing the feed will remove these notifications, and they won't be available for future reference.
In the Anomalies Feed, click
and then click Clear anomalies feed.Anomaly information: Information regarding a single Anomaly Alert.
Investigate: Clicking Investigate opens MegaBill in a new tab with the anomaly configuration (filters) already populated.
Delete an Anomaly:
In the Anomalies Feed, click Delete in a select Anomaly.

Click Yes.
Add a Comment:
In the Anomalies Feed, click Add Comment in a select Anomaly.

Write a comment and click Save.
Create a Jira issue.
Create Custom Anomalies
Navigate to Anomalies.
Click Create Anomaly Alert. The Anomaly Alert Type side window appears.

Choose the Anomaly Alert Type:
Unit Economics Anomaly Go to the specific widget procedure to complete the dashboard setup.
Cost Anomaly
Enable configuration of cost anomalies to detect and flag deviations, triggering alerts to specified endpoints to help identify cost inefficiencies and unexpected trends.
Navigate to Anomalies.
Click Create Anomaly Alert. The Anomaly Alert Type side window appears.

Select Cost Anomaly. The Create Anomaly Alert procedure appears.

Alert Name: Enter an alert name.

Cost Type: Define the cost type.

Select a Cost type. See Cost and Usage for the list of Cost Types.
Load View configuration for the cost. (Optional)
Select a Filter for the cost.
Select what to group by for the cost (Optional). Make sure your selection matches how the costs are organized so the data displays correctly.
Alert Thresholds: Alert thresholds allow you to control when anomalies are surfaced based on cost changes that matter to your organization. By setting specific thresholds, you can filter out noise and focus on meaningful deviations.
For example, setting a threshold of 20% will display only anomalies that exceed that deviation from expected behavior. You can also define a minimum dollar amount—such as $20—to ensure only significant cost spikes trigger alerts. To detect smaller fluctuations, lower either the percentage or dollar threshold. To focus on major anomalies, increase them.
Use alert thresholds to align anomaly detection with your operational norms and cost management goals.

Result: After defining your group and filters, the associated values will appear. You have the option to activate or deactivate each value, allowing you to refine the anomaly alert parameters, making sure it matches exactly what you're looking for.

Alert Endpoints: Easily integrate notifications with endpoints. Select your desired endpoint, ensuring its configuration is completed beforehand, to start receiving anomaly alerts.

Set a default endpoint for this anomaly. If no endpoint is defined for a group-by value, the alert for that value will be sent to this default endpoint. If no default endpoint is set, the alert will be sent to the endpoint specified in the anomalies settings.
Enable sending alerts to endpoints based on group-by values:

Select an endpoint :
Default endpoint - When the toggle is off, all alerts will be sent to the default endpoint you chose in step a.
Selected endpoints and Metadata endpoints -

Click Choose an Endpoint and add any additional endpoints to send the alert.
If you group by a virtual tag, it will automatically send Alerts to its associated Metadata endpoints.
Click
if you would like to disable the Metadata endpoint for this value.
Alert Time Interval:

Define Evaluation Period - Set your preferred time period (Days or Weeks) to check for anomalies. For example, the last 5 days.
Set Comparison Period - This compares the total cost of the current period to the average total cost of several previous periods. For example: You choose 20 days (4 periods). This is compared to the current 5-day total cost to the average total cost of the previous 20 days. Use Case:
You want to evaluate anomalies over a 2-day period compared to the previous 6 days:
Date: Assume today is August 22nd.
Evaluation Period: Calculates the total cost for the chosen evaluation period: The last 2 days (August 19-20).
Comparison Period: Calculates the average of the evaluation period (2 days) over the chosen comparison period: the preceding 6 days (August 12-18).
Alert: An alert is triggered if the time period cost of the evaluation period exceeds the average cost of the comparison period's total costs from the defined thresholds.
Seasonality Check: The Seasonality Check helps reduce false-positive anomaly alerts by recognizing recurring cost patterns. Instead of flagging every cost spike as an anomaly, it checks whether the increase follows a regular weekly or monthly trend before triggering an alert.

Weekday Seasonality
Compares the cost on a specific weekday (e.g., Monday) to the average cost of the same weekday over the past few weeks (e.g., the last 4 Mondays).
An alert is triggered only if the cost exceeds the expected range based on your alert settings.
Monthly Seasonality
Compares the cost on a specific date (e.g., the 1st of each month) to the average cost on the same date over the past few months (e.g., the last 4 months).
An alert is sent if the cost surpasses the historical trend beyond the defined threshold.
This feature ensures that anomalies are detected more accurately, minimizing noise from predictable fluctuations. What Happens When You Enable Seasonality? When the Seasonality Check is enabled, Finout automatically filters out alerts identified as seasonal anomalies: - They won’t appear in your anomaly feed. - They won’t be sent to your configured endpoint. This ensures that your alerts focus only on unexpected anomalies, helping you cut through the noise of predictable cost fluctuations.
Click Save. The Anomaly alert is created and appears under Manage Anomalies. This tab displays a comprehensive table of both custom-created and pre-defined anomalies generated by Finout. Result: A message will appear in your endpoint when a report or anomaly is triggered. For example, email:

Usage Anomaly (Beta)
Usage Anomalies notify you when a usage metric — such as AI tokens, compute hours, storage, or requests — deviates from its expected pattern, so your team can catch operational spikes before they become a cost problem. Unlike a Cost Anomaly, which evaluates spend, a Usage Anomaly evaluates the underlying usage volume, catching issues that don't immediately surface on your bill (for example, usage running under promotional credits). Alerts appear in the Anomalies feed and are sent to your configured endpoints (Slack, email, or Teams).

Navigate to Anomalies and click Create Anomaly Alert. The Anomaly Alert Type store window appears.

Select Usage. The Create Usage Anomaly Alert form appears.

Alert Name: Enter the alert name.

Alert Configuration: Define the parameters of the usage anomaly detection scan.
Load View configuration (optional). Selecting a View populates the filters and group by, which you can then edit.
Filter the usage.
Select what to Group by (optional). Make sure your selection matches how the usage is organized so the data displays correctly.

Usage Units: Define the usage units of the anomaly alert. The available options are driven by your configuration.

Note: If the applied configuration has no supported usage, you'll see an error and can't save the alert. Adjust the configuration to dimensions that expose usage data.

Alert Thresholds: Set the conditions that trigger the alert, in the units of the selected usage type. Choose an above or below direction, a percentage deviation, and an absolute amount. The alert triggers only when both are exceeded — for example, a spike over 20% and over 100,000 tokens. The absolute floor filters out small, low-impact fluctuations.

Set anomaly threshold for every value in the group: Enable this toggle to set thresholds per value instead of across the whole group. Each value in the group then appears with its own threshold.

Alert Endpoint: Select the endpoint to receive alert notifications. Supported endpoint types: email, Slack, and Teams.

Send alerts to endpoints per group of values: Enable this toggle to route alerts to different endpoints based on the group-by value, rather than sending every alert to a single default endpoint. When enabled, you can assign a specific endpoint to each value — so the right team is notified for the usage they own.

Alert Time Interval: Set how often Finout evaluates the alert and the window it measures.
Define Evaluation Period — the recent window (in days or weeks) Finout measures usage over, for example the last 2 days.
Set Comparison Period — the historical baseline the evaluation period is compared against. Finout compares the evaluation period's usage to the average usage of equivalent periods within the comparison window.

Seasonality Check: The Seasonality Check helps reduce false-positive anomaly alerts by recognizing recurring cost patterns. Instead of flagging every cost spike as an anomaly, it checks whether the increase follows a regular weekly or monthly trend before triggering an alert.

Note: Currently, daily seasonality is supported for an evaluation period of 1 to 6 days.
Weekday Seasonality Compares the cost on a specific weekday (e.g., Monday) to the average cost of the same weekday over the past few weeks (e.g., the last 4 Mondays). An alert is triggered only if the cost exceeds the expected range based on your alert settings.
Monthly Seasonality Compares the cost on a specific date (e.g., the 1st of each month) to the average cost on the same date over the past few months (e.g., the last 4 months). An alert is sent if the cost surpasses the historical trend beyond the defined threshold.
What Happens When You Enable Seasonality? When the Seasonality Check is enabled, Finout automatically filters out alerts identified as seasonal anomalies: - They won’t appear in your anomaly feed. - They won’t be sent to your configured endpoint. This ensures that your alerts focus only on unexpected anomalies, helping you cut through the noise of predictable cost fluctuations.
Click Save. The Anomaly alert is created.
Result:
After saving, your usage anomaly appears at the top of the Manage Anomalies tab, alongside your other custom and predefined anomaly configurations.
Once a day, after the data run completes, Finout evaluates the alert against its threshold and interval. When a usage anomaly is detected, it appears in the Anomalies Feed and a notification is sent to your configured endpoints.

Unit Economics Anomaly
Enable configuration of unit economics anomalies to detect and flag deviations, triggering alerts to specified endpoints to help identify cost inefficiencies and unexpected trends.
Navigate to Anomalies.
Click Create Anomaly Alert. The Anomaly Alert Type side window appears.

Select Unit Economics. The Create Anomaly Alert procedure appears.

Alert Name: Enter an alert name.

Unit Economics Configuration: Define what unit economics the alert will monitor. Choose between loading a configuration from an existing Unit Economics widget or setting up a new one.

1. Select a Widget.
2. Select a Cost type.
3. Select a View for the cost.
4. Select a Filter for the cost.
5. Select what to Group by for the cost.
6. Select a Telemetry.
7. Select a Filter for the Telemetry.
8. Select what to Group by for the Telemetry.
Alert Thresholds: Alert thresholds allow you to control when anomalies are surfaced based on cost changes that matter to your organization. By setting specific thresholds, you can filter out noise and focus on meaningful deviations.
For example, setting a threshold of 20% will display only anomalies that exceed that deviation from expected behavior. You can also define a minimum dollar amount, such as $20, to ensure only significant cost spikes trigger alerts. To detect smaller fluctuations, lower either the percentage or dollar threshold. To focus on major anomalies, increase them.
Use alert thresholds to align anomaly detection with your operational norms and cost management goals.

Result: After defining your group and filters, the associated values will appear. You have the option to activate or deactivate each value, allowing you to refine the anomaly alert parameters, making sure it matches exactly what you're looking for.

Alert Endpoints: Easily integrate notifications with endpoints. Select your desired endpoint, ensuring its configuration is completed beforehand, to start receiving anomaly alerts.

Set a default endpoint for this anomaly. If no endpoint is defined for a group-by value, the alert for that value will be sent to this default endpoint. If no default endpoint is set, the alert will be sent to the endpoint specified in the anomalies settings.
Enable sending alerts to endpoints based on group-by values:

Select an endpoint :
Default endpoint - When the toggle is off, all alerts will be sent to the default endpoint you chose in step a.
Selected endpoints and Metadata endpoints -

Click Choose an Endpoint and add any additional endpoints to send the alert.
If you group by a virtual tag, it will automatically send Alerts to its associated Metadata endpoints.
Click
if you would like to disable the Metadata endpoint for this value.
Alert Time Interval:

Define Evaluation Period - Set your preferred time period (Days or Weeks) to check for anomalies. For example, the last 5 days.
Set Comparison Period - This compares the total cost of the current period to the average total cost of several previous periods. For example: You choose 20 days (4 periods). This is compared to the current 5-day total cost to the average total cost of the previous 20 days. Use Case:
You want to evaluate anomalies over a 2-day period compared to the previous 6 days:
Date: Assume today is August 22nd.
Evaluation Period: Calculates the total cost for the chosen evaluation period: The last 2 days (August 19-20).
Comparison Period: Calculates the average of the evaluation period (2 days) over the chosen comparison period: the preceding 6 days (August 12-18).
Alert: An alert is triggered if the time period cost of the evaluation period exceeds the average cost of the comparison period's total costs from the defined thresholds.
Seasonality Check: The Seasonality Check helps reduce false-positive anomaly alerts by recognizing recurring cost patterns. Instead of flagging every cost spike as an anomaly, it checks whether the increase follows a regular weekly or monthly trend before triggering an alert.
Note: Currently, daily seasonality is supported for an evaluation period of 1 to 6 days.

Weekday Seasonality
Compares the cost on a specific weekday (e.g., Monday) to the average cost of the same weekday over the past few weeks (e.g., the last 4 Mondays).
An alert is triggered only if the cost exceeds the expected range based on your alert settings.
Monthly Seasonality
Compares the cost on a specific date (e.g., the 1st of each month) to the average cost on the same date over the past few months (e.g., the last 4 months).
An alert is sent if the cost surpasses the historical trend beyond the defined threshold.
This feature ensures that anomalies are detected more accurately, minimizing noise from predictable fluctuations. What Happens When You Enable Seasonality? When the Seasonality Check is enabled, Finout automatically filters out alerts identified as seasonal anomalies: - They won’t appear in your anomaly feed. - They won’t be sent to your configured endpoint. This ensures that your alerts focus only on unexpected anomalies, helping you cut through the noise of predictable cost fluctuations.
Click Save. The Anomaly alert is created. Result: After saving the anomaly, your anomaly will appear under Manage Anomalies. This tab displays a comprehensive table of both custom-created and pre-defined anomalies generated by Finout.
Commitment Expiration Anomaly
Commitment Expiration Alerts notify you when a commitment plan is approaching its expiration date, so your team can act before it lapses. Commitment expiration alerts appear in the Anomalies Feed and can be sent to your configured endpoints (Slack, email, or Teams) based on your needs.

Navigate to Anomalies and click Create Anomaly Alert. The Anomaly Alert Type store window appears.

Select "Commitment" Alert. The Create Commitment Expiration Alert form appears.

Alert Name: Enter the alert name.

Cloud Provider: Select a cloud provider: AWS or Azure.

Note: These are the cloud providers currently supported in My Commitments. Only providers with existing commitments in your account will appear as options.
Alert Configuration (Optional): Define the scope of commitments this alert will monitor.
Commitment Type: Select a commitment type. Available options depend on the selected cloud provider. For example: AWS — Reserved Instances (RI), Savings Plans (SP). This field defaults to all types selected.

Filters: Narrow the alert to specific commitments. Only commitments that match all selected filters will trigger the alert. Available values are based on the commitments that are available in your My Commitments.
AWS
Reserved Instances
Service, Instance Type, Region, Operating System, Offering Class, Payment Option, Account Name, Reservation Term.
AWS
Savings Plans
Saving Plan Type, Term, Payment Option, Account Name.
Azure
Reservations
Instance Type, Region, Reservation Term, Reserved Resource Type, Subscription Name, Auto Renew Status.
Azure
Savings Plans
Scope Type, Reservation Term, Saving Plan type, Subscription Name, Auto Renew Status.
Alert Thresholds: Set when to be notified before a commitment plan expires.
Remind me about this plan expiration every (Optional) — enable the toggle to receive recurring reminders after the initial alert. Set the frequency and unit (Days or Weeks).

Alert Endpoints: Select the endpoint to receive alert notifications. Supported endpoint types: email, Slack, and Teams.

Click Save. The alert is created and appears in the Manage Anomalies tab.
Result: When a commitment plan matches the configured filters and reaches the expiration threshold, an alert appears in the Anomalies Feed, and a notification is sent to the configured endpoint. For example, Slack:

Manage Custom Anomalies
The Manage Anomalies tab displays a comprehensive table of both custom-created and pre-defined anomalies generated by Finout.
Navigate to Anomalies and select the Manage Anomalies tab.

Search for the relevant anomaly: Use the search bar for a direct query or apply filters to narrow down results.
Toggle off an anomaly to disable alerts for that specific issue.
Click
beside the relevant anomaly and then select one of the following:Edit: Edit the Anomaly Alert and click Save.

Duplicate: make changes to the Duplicated Alert and click Save.

Delete: Deletes the Anomaly Alert.
Predefined Anomalies
Finout provides pre-configured anomalies out of the box that can be customized to meet your specific requirements. You can toggle these anomalies on or off, or duplicate them as a foundation for creating custom anomalies, ensuring they align with your needs.
Finout automatically detects the following predefined anomalies:
AWS: Regions, Sub Service, Account Name, Entity Name, Charge Type
Azure: Service, Meter Region, Meter Sub Category, Service Family, Consumed Service
GCP: Project ID, Compute Machine Spec, Folder, Project Name, Project Number, Region, SKU description, Services
Global: Cost Center, Extended Support
Kubernetes: deployment, demonset, k8s_namespace, cronjob
SnowFlake: cost type, warehouse_name, user name, account, database name
DataDog: Product, Organization, Sub-Product, Index, Metric Name, Region, Service, Status, Usage Type
All Virtual Tags
OpenAI: Project ID, Model, Token Type, API Key
OCI: Services, Regions, Tenant ID, Compartment Name
Anthropic: Cost per workspace name, Token type, Model for Anthropic.
Cursor: Model, User, Kind
CircleCI: Resource Class, Workflow Name, Project Name
Databricks: SKU Name, Owner, Workspace ID
GitHub: Actions, Copilot , SKU, Organization Name
Grafana: Service Name, Service Category, Resource Name
Manage Predefined Anomalies
Navigate to Anomalies and select the Manage Anomalies tab.

Search for the relevant anomaly: Use the search bar for a direct query or apply filters to narrow down results.
Toggle off an anomaly to disable alerts for that specific issue.
To duplicate, select
beside the relevant anomaly
If you choose to duplicate, set a name for the duplicated anomaly and adjust all fields accordingly.When you modify a predefined anomaly, a new custom anomaly is created with the revised settings, and the original predefined anomaly is deactivated.
FAQs
How long is anomaly data retained?
Anomalies are retained for 3 months. After that period, they're automatically removed from the Anomalies Feed and are no longer available for investigation or reference.
Why does the comparison period need to be a multiple of the evaluation period? The comparison period must be a multiple of the evaluation period to ensure consistency in calculations. This allows Finout to calculate the total cost of each evaluation period within the comparison period and determine an accurate average. For example, if your evaluation period is 3 days, the comparison period could be 9 days (3 evaluation periods) but not 10 days, ensuring reliable and consistent anomaly detection.
Why can’t I choose arbitrary intervals like 3 weeks compared to 4 weeks?
To maintain accurate comparisons, the comparison period must align with the evaluation period to ensure equal, consistent time intervals. This alignment ensures anomalies are detected based on reliable averages derived from comparable time intervals.
Is there a limit to how many anomaly alerts I can receive per day?
Yes. Each account has a maximum number of alerts sent per day:
Cost, Usage, and Unit Economics: a combined maximum of 150 per day, prioritized by highest anomaly value.
Run Rate alerts: a separate maximum of 100 per day, prioritized by the highest budget anomaly value.
Commitment Expiration alerts: a separate maximum of 150 per day, prioritized by closest expiration date.
These are the maximum values. You can set a lower limit in the Anomalies Settings.
Is there a limit to how many values I can set thresholds for in anomaly alerts?
Yes. To ensure anomaly alerts save and run reliably at scale, thresholds can only be set for the top 1,500 values by cost when using the “set thresholds by value” or “set endpoints by value” options.
Is there a limit to anomaly alert data values?
Yes. To ensure anomaly alerts run reliably and efficiently, Finout automatically analyzes only the top 10,000 values by cost. When the data exceeds this limit, only the most cost-significant values will be analyzed.
Why does the "Investigate" button open MegaBill with a ~60-day date range, even for short-interval alerts?
This is the default behavior. When you click Investigate, MegaBill opens with a broader historical window, not the alert's evaluation period, so you can see the full cost trend for that filter and better identify the root cause. The date range is the same across all alerts in the account.
You can adjust the date range directly in MegaBill after it opens.
Why isn't seasonal detection available for my anomaly?
Seasonal detection is only supported when the anomaly is configured with daily time aggregation and an evaluation period of 6 days or fewer. If either condition isn't met, the option is disabled automatically.

Why does the anomaly feed show a cost spike, but MegaBill looks normal when I click Investigate?
Finout automatically excludes certain line item types from anomaly evaluation to reduce noise. These exclusions are applied in the background on top of any filters you configured in the anomaly rule:
GCP:
Credits Typeis notPROMOTIONAWS:
Charge Typeis not one ofCredit,Tax
When you click Investigate on a specific anomaly alert, MegaBill opens with only the filters you defined in the anomaly rule — the automatic exclusions are not carried over. This means the cost data in MegaBill may appear higher than what triggered the alert.
To replicate the exact view Finout used to detect the anomaly, add the relevant filters above manually in MegaBill after clicking Investigate.
Last updated
Was this helpful?