Updated on 2026-05-22 GMT+08:00

Analyzing Cost Anomalies

Cloud costs are variable and cloud resources are scalable. After enterprises migrate their services to Huawei Cloud, one of the challenges they face is how to monitor unexpected expenditure spikes. Cost Center provides Cost Anomaly Detection to help you identify cost anomalies in a timely manner and analyze and track these anomalies when they occur.

Introduction to Cost Anomaly Detection

Cost Anomaly Detection uses machine learning to establish a specific expenditure model for you based on your historical pay-per-use and yearly/monthly expenditures. This function helps identify cases and root causes for cost surprises by comparing them to forecasted amounts. For details about cost anomaly detection rules, see Detection Rules.

After you create alert notifications for monitors of a specific type (such as all services, linked accounts, cost tags, cost categories, or enterprise projects), Cost Center will notify the designated recipients of the cost anomalies whose impact has exceeded the specified threshold at a scheduled time.

You can view all cost anomalies associated with a monitor and analyze the potential causes of anomalies. You are advised to provide feedback on cost anomaly detection to help improve your consumption model and identify possible anomalies more accurately.

Example Scenarios

After receiving an email about cost anomalies, you may want to identify possible causes and do further analysis.

Step 1: Viewing Anomaly History

Suppose you have received a cost anomaly notification and are redirected to the cost anomaly detection page.

  1. After a global monitor is automatically created, you will receive a notification from Cost Center. This notification is not a cost anomaly alert.
  2. Cost Anomaly Detection is free of charge.
  1. Check your email for cost anomaly notifications.
  2. In the email, click View Details in the Operation column. You will be redirected to the Cost Anomaly Details page in Cost Center.

    Table 1 Fields in an email notification of cost anomalies

    Field

    Description

    Detection Date

    Date when a cost anomaly is detected.

    NOTE:

    Cost anomalies are not recorded in real time. Cost Center supports user-created cost monitors . For details about the delay, see Delay in Generating Cost Anomalies.

    First Occurred

    Date when a cost anomaly actually occurred.

    This date precedes the detection date by two days for system-created cost monitors and by one day for user-created ones. For details, see Delay in Generating Cost Anomalies.

    Duration

    The length of time a cost anomaly persists for. The anomaly might not be only temporary.

    Severity

    Severity of an anomaly. Low severity means the actual expenditure is only slightly higher than the maximum expected expenditure when the anomaly is detected, whereas high severity indicates a significant difference between the expected and actual expenditure. For details, see Severity of Cost Anomalies.

    Cost Anomalies

    Pay-per-use or yearly/monthly costs.

    For details, see Monitoring Scope of Cost Monitors.

    Monitor

    Name of the monitor that detects a cost anomaly.

    Service Type

    Name of the service where a cost anomaly is detected.

    Account Name

    Account that generates abnormal costs.

    This field only displays the enterprise master account and its member accounts associated for unified accounting management.

    Cost Impact

    • Total cost impact

      The sum of the daily cost impact over the anomaly monitoring period.

    • Cost impact
      Subject to the latest data of the day when you view the cost anomaly over the anomaly monitoring period.
      • Cost impact on pay-per-use resources = Actual cost on the current day – Maximum forecasted cost
      • Cost impact on yearly/monthly resources = Cost for the current month – Cost for the same period in the previous month

    For details, see Rules for Calculating Cost Impact.

    Example: Suppose you have a cost anomaly record from April 10 to April 12, the anomaly lasts for three days, the impact cost on April 10 is $100 USD, on April 11 is $200 USD, and on April 12 is $300 USD. In this case, the total cost impacted is $600 USD.

    Next Step

    Click View Details to go to the anomaly details page.

  3. View cost anomaly details. As shown in the following figure, a cost anomaly in a yearly/monthly subscription was generated on December 3, 2024. The cost impact was $8.16 USD over 30 days, and the service type involved is EVS.

    On the Cost Anomaly Details page, you can see the basic information and potential causes of the cost anomaly.

Step 2: Analyzing Causes of Cost Anomalies

  1. Under Possible Causes, do preliminary analysis. For example, if you have renewed the yearly/monthly subscription in question, the cost increase is considered a normal business result, and you can confirm that it was a false positive. Your feedback will help improve the anomaly detection model.

  2. Further analyze the anomaly. If you think you are not aware of the increase, you are advised to click View Cost Analysis in the Operation column for further analysis.

  3. Determine whether the unforeseen anomaly is accurate. In this example, a new purchase order line was generated for EVS on December 2, 2024, costing $8.16 USD. You need to check whether the new purchase was an anomaly or not.

  4. Analyze potential causes of the anomaly from a specific perspective. For example, if you want to analyze the source of the anomaly from the business perspective, you can select Enterprise Project, Cost Tag, or Cost Category to group the costs.

    As shown in the following figure, the EVS cost ($8.16 USD) generated on December 2, 2024 was assigned to the default enterprise project.

  5. Set Grouped By to Resource Name/ID to identify the resources that have generated expenditures.

    As shown in the following figure, the costs of EVS volume-4c2a b9ef14be-8f1e-46a5-a31d-6c5196082937 purchased on December 8, 2024 and December 9, 2024 were $0.26 USD and $6.38 USD, respectively.