Monitors

Monitors let you set up cost anomaly detection across your cloud and AI spend, scoped to the accounts, services, users, or other cost categories you care about. When a Monitor detects a significant, unexpected change in spend, CloudZero opens an Incident so your team knows exactly what happened and can investigate.

ℹ️

The Monitors feature is in public preview. To turn it on, open Labs from your profile menu and enable Monitors for yourself or, if you are an admin, for your whole organization. It's the updated and improved version of Anomaly Detection: you choose the spend to watch and the thresholds that matter, and CloudZero opens an Incident your team can investigate and resolve. Monitors will eventually replace Anomaly Detection, and you can use both in the meantime.

In CloudZero, select Monitors from the left navigation.

CloudZero Monitors page in the left navigation, showing the Incidents and Monitors tabs

How Monitors work

A Monitor watches a specific slice of your spend. CloudZero's forecasting model evaluates that spend every day and detects anomalies automatically. An optional threshold on the Monitor then filters which detected anomalies become Incidents. CloudZero opens Incidents on the Incidents tab, and you create and manage Monitors on the Monitors tab.

What the Incidents tab shows

The Incidents tab gives you a complete picture of all detected Incidents across your environment.

  • Total Cost Impact: The combined cost impact of Incidents detected in the last 30 days
  • Total Incidents: The number of Incidents detected in the last 30 days
  • Incident Count: A visualization showing how many Incidents are in each status (Active, Investigating, Resolved), so you can see where your team's attention is needed

Below the summary, a results table lists all Incidents with their status, title, 30-day spend trend, cost impact, spend recovered, the Monitor that raised them, when they started, and when they were last updated.

Find an Incident

Quick filters above the table let you switch between Incident states with one click:

Quick filterShows
ActiveIncidents that are newly detected and not yet being investigated
InvestigatingIncidents your team is actively investigating
ResolvedIncidents that have been closed, either by your team with a Resolution Reason or automatically by CloudZero
AllAll Incidents regardless of status

View Incident details

Select an Incident to open the detail flyout. The flyout gives you the full context of the Incident and lets you investigate and take action.

CloudZero Incident detail flyout, Overview tab, showing the summary, cost chart, and Contributing Resources table

Overview tab

The Overview tab shows the complete picture of the Incident:

  • Summary: An AI-generated description of when the anomalous spend was identified and whether it is ongoing
  • Cost Impact: The difference between expected and actual spend, shown at the top of the flyout
  • Cost chart: A chart showing spend around the time of the Incident, with a View in Explorer option that opens Explorer with the Incident's filters already applied
  • Details: The Monitor that raised the Incident, when it started, its duration, and whether spend is ongoing
  • Contributing Resources: A table of all resources involved in the Incident, showing each resource's name, service, account, region, and provider (select a resource to view it in Explorer)

Activity tab

The Activity tab shows a timeline of the Incident's lifecycle: when it was created, each time its status changed (including the Resolution Reason when it was resolved), and whether CloudZero resolved it automatically. Each entry has a timestamp. When a person changes the status, the entry also shows who made the change.

Manage an Incident

You can change an Incident's status from the flyout or directly from the results table.

Incident statuses

  • Active: The Incident has been detected but no action has been taken.
  • Investigating: Someone is actively investigating the Incident.
  • Resolved: The Incident is closed, either by your team or automatically by CloudZero.

Resolve an Incident

To resolve an Incident yourself, change its status to Resolved and select a Resolution Reason:

  • Intentional: The spend change was expected.
  • Remediated: The underlying cause has been fixed.
  • Not an Anomaly: The spend change was not actually anomalous.

You can add optional details to explain the resolution. If the Incident's spend is still ongoing, CloudZero warns you before you resolve it.

If no one resolves an Incident manually, CloudZero automatically resolves it once its spend has been back to normal for 7 days.

What the Monitors tab shows

Select the Monitors tab to see and manage your Monitors. The results table shows each Monitor's name, its status (Active if it's running, Paused if it isn't), how many open Incidents it has raised, and when it last triggered. Use the All, Active, and Paused quick filters above the table to narrow the list. Select New Monitor to create a new Monitor.

CloudZero Monitors tab showing the results table and the New Monitor button

Create a Monitor

  1. Select New Monitor.

  2. Name the Monitor and, optionally, add a description.

  3. Select a Cost Type: Amortized Cost, Billed Cost, Discounted Cost, Discounted Amortized Cost, Invoiced Amortized Cost, On-Demand Cost, or Real Cost. A Monitor watches one Cost Type; create a separate Monitor to track a different one. For definitions, see Cost Types.

  4. (Optional) Choose a Group By Dimension, such as account, service, or user.

  5. (Optional) Add filters to scope the Monitor to the spend you care about.

  6. Review the cost preview to confirm the Monitor matches the spend you expect before saving.

  7. (Optional) Set a threshold to filter which detected anomalies become Incidents:

    • Percentage of spend: How far above CloudZero's forecast the day's spend must be, as a percentage of the forecast
    • Minimum cost impact: How far above CloudZero's forecast the day's spend must be, in dollars

    If you set both, the day's spend must clear both before CloudZero raises an Incident. For example, if CloudZero forecasts $1,000 for a day and you set Percentage of spend to 20% and Minimum cost impact to $500, CloudZero raises an Incident only when that day's spend reaches $1,500. If you leave both fields blank, every anomaly CloudZero's forecasting model identifies becomes an Incident.

  8. Choose where CloudZero sends notifications when the Monitor opens an Incident. You can use either option or both:

SectionWhat to enter
Notification RecipientsOne or more email addresses, separated by commas
Slack ChannelOne Slack Channel ID (requires the Slack integration, which also explains how to find a Channel ID)
  1. Select Create Monitor.
CloudZero Create Monitor drawer showing Cost Type, Group By, filters, cost preview, thresholds, and notification recipients

After you save a Monitor, CloudZero evaluates its scope as soon as the next cost data ingest completes, then once a day after that.

Edit, pause, or delete a Monitor

To edit a Monitor: Select Edit from the Monitor's row, update any of its settings, and select Save Monitor.

To pause or resume a Monitor: A paused Monitor is not evaluated and generates no new Incidents. Select Pause or Resume from the Monitor's row, or from its details flyout.

To delete a Monitor: Select Delete from the Monitor's row and confirm. Deleting a Monitor also deletes its Incidents.

System Monitors

CloudZero runs three system Monitors for you. They're already watching your spend when you turn on Monitors, so you see Incidents without building anything:

MonitorWhat it watches
Account MonitorSpend in each account, for every cloud provider
Service MonitorSpend on each service within each account
AI User MonitorAI spend for each user, wherever CloudZero can identify both the user and the model provider

System Monitors track Real Cost across all of your spend, with no filters and no threshold, so every anomaly they detect becomes an Incident. When the Account Monitor and the Service Monitor both detect the same spike, CloudZero shows the Service Monitor's Incident, since it pinpoints which service changed, and hides the duplicate account-level Incident.

System Monitors can't be edited, paused, or deleted. To choose who receives their notifications, select Edit from the Monitor's row, add email addresses or a Slack Channel ID, and select Save Notifications.

Putting it together: from Incident to resolution

Set up a Monitor once, and CloudZero takes it from there. Every day, CloudZero checks the spend you scoped against what it expects to see and opens an Incident when actual costs deviate from expected trends.

From the Incidents tab, open the flyout to see the AI-generated summary, the cost chart, and the resources driving the change. Move the Incident to Investigating while your team looks into it, then resolve it with the Resolution Reason that fits: Intentional, Remediated, or Not an Anomaly.

ℹ️

Have questions or feedback? Reach out to your account manager.


Did this page help you?