Skip to main content

Azure anomalies

AvailableReviewed 24 August 2026

Anomalies on the Azure chip are cost movements that differ from a 30-day baseline (two standard deviations). They are signals. Confirm subscription, resource group and meter before you assign a resize or a ticket.

Azure anomalies table with Virtual Machines, Bandwidth and Azure SQL spikes
Sample August window. Virtual Machines +20.1% is the first item to open.

Open Azure anomalies​

  1. Open Anomalies.
  2. Select Azure.
  3. Sort by deviation.
  4. Open the largest row.

What a typical Azure spike looks like​

ServiceOften meansNext check
Virtual MachinesScale-out, forgotten staging, SKU upgradeResource group, VM list, activity log
BandwidthEgress to internet or paired regionNSG, CDN, backup jobs
Azure SQL DatabaseDTU/vCore change, geo-replicationService tier, backup retention
AKSNode pool scaleCluster autoscaler, failed drain
Blob StorageLifecycle policy off, dump loadContainer growth, replication

Investigate​

  1. Note actual, expected, subscription and date.
  2. In Cost Explorer, filter to that service and day.
  3. Drill to resource group, then resource.
  4. In Azure Portal, open Activity log on that resource group for the same window.
  5. Assign an owner from tags (owner, product) or the subscription default.

Do not accept a rightsizing recommendation on the same resources until you know the spike was not a legitimate scale event.

Expected result​

The largest Azure anomaly has a cause, an owner and a next action (leave it, raise a ticket, or open a recommendation).