All Products
Search
Document Center

Expenses and Costs:Anomaly detection

Last Updated:Jan 19, 2026

Anomaly detection uses an AI algorithm to identify unusual fluctuations in your spending. It provides automatic monitoring, detection, and alerting for unexpected costs, for timely insights into cost anomalies.

Enable anomaly detection

Note

Anomaly detection is a free service provided "as-is" using algorithms to identify suspected usage anomalies. By using this feature, you acknowledge that detection may be inaccurate, incomplete, or delayed. Alibaba Cloud does not guarantee 100% stability and is not liable for any financial losses resulting from undetected anomalies or false alerts.

On the Anomaly Detection page, toggle Enable Detection.

After you enable detection, results are available the next day. Detection results appear only when an anomaly is found.

image

Note
  • A management account can view anomaly detection results for member accounts within its organization. However, you can only view the results for one member account at a time.

  • Enabling detection or alerts applies only to the currently logged-in account. To use this feature for multiple accounts in an enterprise organization, you must enable it separately for each account.

Supported services

Anomaly detection supports the following cloud services.

Code in console

Service name

ecs

ECS (Pay-as-you-go)

vm

ECS (Subscription)

yundisk

Elastic Block Storage (EBS)

snapshot

Snapshots

ddh_post

Dedicated Host (Pay-as-you-go)

oss

Object Storage Service (OSS)

naspost

File Storage NAS (Pay-as-you-go)

ots

Tablestore (Pay-as-you-go)

eip

Elastic IP Address (EIP) (Pay-as-you-go)

nat_gw

NAT Gateway (Pay-as-you-go)

slb

Server Load Balancer (SLB) (Pay-as-you-go)

ens

Edge Node Service (ENS)

cbn_bwp

Cloud Enterprise Network (CEN) (Subscription)

cbn_bwp_pre_mkt

CEN (Cross-border) (Subscription)

cbwp

Internet Shared Bandwidth (Pay-as-you-go)

cbwp_pre

Internet Shared Bandwidth (Subscription)

cdn

Content Delivery Network (CDN)

cdt_internet_public_cn

Cloud Data Transfer (CDT) (Internet) (Chinese Mainland)

dcdn

Edge Security Acceleration (ESA)

ipv6bandwidth

IPv6 Internet Bandwidth (Pay-as-you-go)

ri

Express Connect – Router Interface (Pay-as-you-go)

pconn_pre

Express Connect – Resource Usage Fee (Subscription)

ads

AnalyticDB for MySQL (Pay-as-you-go)

polardb_sub

PolarDB (Subscription)

rds

ApsaraDB RDS (Pay-as-you-go)

rords

RDS Read-only Instance (Pay-as-you-go)

csk_groupservice_public_cn

Container Service for Kubernetes (ACK) Enterprise Edition

eci_betav1

Elastic Container Instance (ECI)

arms

Application Real-Time Monitoring Service (ARMS) Trial Edition

sls

Simple Log Service (SLS)

odps

MaxCompute (Pay-as-you-go)

odpsplus

MaxCompute (Subscription)

ons

ApsaraMQ

dyvms_voiceSip_public_cn

Voice Service (VS) (SIP Trunking)

snsu_dci_public_cn

Edge Network Acceleration (ENA)

imm

Intelligent Media Management (IMM)

live

ApsaraVideo Live

mpaas_gov_public_cn

Mobile PaaS (mPaaS)

pcdn

P2P Content Delivery Network (PCDN)

pds_01_public_cn

Drive and Photo Service

saf_pos

Fraud Detection (Pay-as-you-go)

Note

For subscription products, anomaly detection only supports their pay-as-you-go billable items.

Set anomaly detection sensitivity

Click Detection Settings and drag the slider to adjust the sensitivity for anomaly detection. A higher sensitivity value makes the system more likely to detect an anomaly.image

  • Cost Impact: The absolute difference between the actual cost and the boundary of the threshold.

  • Threshold: The range of normal cost fluctuations, calculated by the anomaly detection algorithm based on your set sensitivity and historical spending data. The shaded blue area in the cost trend chart represents this range.

    Note
    • If the actual cost falls within the threshold, the algorithm considers the fluctuation normal and does not report an anomaly. If the actual cost exceeds the upper or lower bounds of this range, the algorithm flags it as an anomaly.

    • The sensitivity setting affects the threshold. A higher sensitivity results in a narrower threshold, which makes detecting anomalies more likely.

Configure anomaly alerts

Toggle Enable Alerting to activate alerts. When a detected cost impact or severity level meets the configured threshold, the system automatically sends an alert notification.

Click Set Alert Threshold to configure alert thresholds and notification methods.

image

  • If you select Cost Impact as the Alert Condition, enter a specific cost amount as the threshold.

  • If you select Severity as the Alert Condition, you can choose Minor, Major, Critical, or Very Critical as the threshold. The definition of each severity level depends on the cost trend:

    Severity

    Definition

    Minor

    Major

    Critical

    Very Critical

    Definition for an upward cost trend

    Cost impact USD ≤ 20,

    or cost impact ≤ 20% of the upper bound of the threshold

    Cost impact USD > 20,

    and 20% of the upper bound of the threshold < Cost impact ≤ 100% of the upper bound of the threshold

    Cost impact USD > 20,

    and 100% of the upper bound of the threshold < Cost impact ≤ 500% of the upper bound of the threshold

    Cost impact USD > 20,

    and cost impact > 500% of the upper bound of the threshold

    Definition for a downward cost trend

    Cost impact USD ≤ 20,

    or cost impact ≤ 30% of the lower bound of the threshold

    Cost impact USD > 20,

    and 30% of the lower bound of the threshold < Cost impact ≤ 80% of the lower bound of the threshold

    Cost impact USD > 20,

    and cost impact > 80% of the lower bound of the threshold

    -

  • Enable the alerting feature for critical anomalies: If you enable this option, you receive timely alerts for critical and very critical anomalies. Alerts can be sent as soon as 9 hours after the actual spending occurs. You cannot view the details of an anomaly on the same day it is detected; you can do so the next day on the details page.

    Enabling early alerts for critical anomalies increases the frequency of alert notifications. If you find these notifications disruptive, disable this feature or reduce the number of recipients.

Evaluate detection results

When the system detects a cost anomaly, it displays the results in the Anomaly Details list.

In the Actions column, click View Details to see information such as the detection time, the affected product and account, and the cost trend before and after the anomaly. Click View Cost Analysis on an anomaly point to navigate to the Cost Analysis page and verify the detection result.

Provide feedback on the detection results to help train the algorithm. The more feedback you provide, the more accurate the detection becomes.

  • Accurate anomaly: This confirms that the detection identified a genuine business anomaly. The system will continue to flag similar patterns as anomalies.

  • Non-issue: This indicates the cost fluctuation was expected or had minimal impact.

  • False positive: This indicates the system's detection was incorrect and the event was not a real anomaly.

image