Catch cost spikes the day they start
CloudLens learns the normal range for each service, flags spend outside it, and forecasts every budget from the current pace, so you hear about an overrun while there is still time to act.
- 1EKS leaves its expected range
On Aug 20, Amazon EKS in prod-core for Checkout hits $1,002 against an expected $677. The top driver is Checkout namespace node hours.
- 2Slack gets the High alert
The alert lands in #cloud-cost-alerts with scope, expected and actual cost, so on-call knows whose it is.
- 3Set it to Investigating
Changing the status shows the team someone already owns the hunt.
- 4Resolve it
Once the cause is fixed, the anomaly moves to Resolved and stays in history with its timeline.
Most cost spikes are found on the invoice
By then the money is spent. These are the usual ways a spike slips through.
Runaway spend nobody notices
What usually happens: A load test leaves a node group scaled out for three weeks, and the first person to notice is whoever reads the invoice.
How CloudLens resolves it: The anomaly appears the day spend leaves its expected range, with expected cost, actual cost and the deviation.
ResolvedAlerts that fire all day
What usually happens: One global threshold either fires all day on big services or never notices a small one doubling.
How CloudLens resolves it: Each service is measured against its own recent pattern, and only Medium and High anomalies post to Slack.
ResolvedBudgets checked after the money is spent
What usually happens: Budgets get checked in the monthly review, after the money is already spent.
How CloudLens resolves it: Every budget is forecast daily. When the projection crosses it, it is marked Projected to exceed budget and the owner is emailed.
ResolvedHow Priya handled the checkout EKS spike
From the first alert to a resolved anomaly and a budget back under its limit, in one working day.
Lumora Retail is a fictional company. The people, names and numbers are sample data.
Anomaly detected on Amazon EKS
Slack posts it to #cloud-cost-alerts
Moves it to Investigating
Finds the cause in Cost Explorer
Scales it back and resolves it
The Checkout budget recovers
Get alerts the day spend jumps
Every anomaly gets an owner and a status
Each anomaly shows expected cost, actual cost, the deviation and the scope that drove it. Move it through a status and keep the history.
Work anomalies like a queue
- Expected cost, actual cost and deviation
- Open, then Investigating, then Resolved
- False Positive stays in history
- 1Read the queue at a glance
3 Open, 2 Investigating, 11 Resolved in the last 30 days and 1 False Positive.
- 2Check the Amazon S3 row
Sandbox spend for Growth is up 60.5%, but it is Low severity and the amounts are small.
- 3Mark it False Positive
The count goes to 2 and the row stays listed, so the record of the call is kept.
Know about an overrun while you can act
- Threshold alerts, 80% by default
- Projected to exceed budget
- Budget history by month
- 1Check the September budgets
Checkout has spent $38,880 of $48,000 and passed the 80% line. Data Platform and Growth are on track.
- 2Read the forecast line
At the current pace Checkout crosses its budget around Sep 25, about $3,840 over. The card is marked Projected to exceed budget.
- 3The owner gets an email
The alert says $38,880 of $48,000 is spent with 18 days left, and September lands at $51,840.
- Slack for Medium and High
- Email for budget thresholds
- Share recommendations to Teams
- 1A High anomaly posts at 09:14
Amazon EKS +48.1% in prod-core for Checkout, with expected and actual cost and a View anomaly button.
- 2Ana shares a recommendation
At 11:02, rightsizing checkout-worker-03 from m6i.2xlarge to m7g.xlarge lands in the same channel at $1,140/mo, owned by Checkout.
- 3Other alerts follow their routes
A Medium Bedrock anomaly posts at 14:37. An orders-db Reserved Instance recommendation goes to Microsoft Teams, and budget alerts go to owners by email.
Fewer surprises, fewer false alarms
An expected range per service
Anomalies are measured against each service’s own recent pattern, not a single threshold for everything.
Forecasts that arrive early
A budget alert on day 12 starts a conversation. The same alert on day 30 starts a post-mortem.
Routed by severity
Only Medium and High anomalies interrupt a channel. Everything else is still listed in the app.
Anomalies & Budgets questions
CloudLens compares each day’s spend with the expected range for that service and scope, and records expected cost, actual cost and the deviation.
Medium and High severity anomalies post to the Slack channel you connect. All anomalies, including Low, are listed in the app and can be emailed.
It closes the anomaly as noise and keeps it in history, so the record of what happened is not lost.
From month-to-date spend and the current daily pace. When the projection crosses the budget, the budget is marked “Projected to exceed budget”.
Ready to see CloudLens in action?
Connect a read-only AWS role or Azure service principal. We'll walk you through your bill, your security graph and the first things worth fixing.
