Skip to main content

Investigate a cost spike

AvailableReviewed 21 August 2026

Use this guide when an anomaly is large enough to mention in a FinOps review.

Anomaly detail for an EC2 spike with baseline chart and contributing dimensions
Sample investigation. The owner comes from tags or account metadata in the export.

Steps

  1. Open Anomalies and select the row.
  2. Read actual vs expected and the date of the movement.
  3. Note account, service, usage type, region and owner.
  4. Confirm the movement against Cost Explorer for the same day.
  5. Decide:
    • Expected change (scale event, launch, seasonal) — document it and close the review.
    • Unexpected — assign an owner and, if relevant, open a recommendation.

Expected result

You can say what moved, when, who owns it, and whether action is required.

Common issues

IssueCheck
No ownerTags on the resource; account default owner
Actual looks too smallProvider chip and date
Spike repeats dailyBaseline may include the spike — widen the window in Explorer