User Guide

Alerts

Anomaly detection and budget breach alerts with configurable rules and email notifications.

Two alert types#

📈

Anomaly alerts

Cost spikes detected by comparing current resource costs against rolling baselines (7/14/30-day windows). Triggers when deviation exceeds your configured threshold.
💵

Budget alerts

Threshold breaches on your configured budgets. Triggers when actual spend or forecasted spend crosses warning (80%) or critical (100%) thresholds.

Alerts tab#

The Alerts page has two horizontal tabs: Alerts and Rules.

The Alerts tab shows:

  • ✓Summary stat cards (total, triggered, acknowledged, resolved)
  • ✓Type filter (All / Anomaly / Budget)
  • ✓Status filter (All / Triggered / Acknowledged / Resolved)
  • ✓Severity filter (Critical / High / Medium / Low)
  • ✓Alert cards grouped by subscription (collapsible, collapsed by default)

Alert cards#

Each alert card shows:

  • ✓Type badge (purple = budget, blue = anomaly)
  • ✓Severity color coding (critical = red, high = orange, medium = yellow, low = blue)
  • ✓Cost comparison grid (anomaly: current vs baseline + deviation; budget: spend vs budget + usage %)
  • ✓Forecast alerts show 'Projected' / 'Forecast' labels
  • ✓Actions: Acknowledge, Resolve, Email (inline recipient input)

Alert rules#

The Rules tab lets you create and manage detection rules:

  • ✓Name and scope (subscription → resource group or resource)
  • ✓Threshold type: percentage (50% spike) or absolute ($200 increase)
  • ✓Baseline window: 7, 14, or 30 days
  • ✓Severity assignment (low / medium / high / critical)
  • ✓Email notification toggle with recipient list
  • ✓Cooldown period (default 24 hours) to prevent alert storms
Default behavior
If no user-defined rules exist, the detection engine uses system defaults: 50% spike or $200 absolute increase, whichever is lower.

Detection cycle#

The anomaly detection engine runs every 4 hours (after cost data refresh):

  1. Fetch current month's resource-level costs from the latest snapshot
  2. Compute rolling baseline for each resource/RG over the configured window
  3. Compare current cost vs baseline for each monitored scope
  4. Create Alert records for deviations exceeding thresholds
  5. Send email notifications (if configured)
  6. Auto-resolve alerts where costs have returned to normal
Tip
Budget alerts also run on a 4-hour cycle, checking both actual spend and forecasted month-end spend against your configured thresholds.