Saltar a contenido

Anomalies

Anomalies are spend spikes with attribution — a day whose cost broke its typical weekday or month-end weekday baseline. Koltto does not auto-fix them.

This is not inventory. New resources and config diffs live on Inventory Changes.

The period in the top bar both filters stored rows and scans that window the first time you open the page or when the period changes. Optional email for the same spikes still evaluates the last 30 days on Budgets & Alerts.

How to use it

  1. Read Impact (extra spend vs typical) and the count of anomalies in the period. Drag the chart to a custom date range. When that range is three days or less, Hour is spend-by-hour (UTC), not anomaly-by-hour — detections stay daily. Header presets restore a standard window.
  2. The list shows a plain-English summary, severity, and status. Click status, severity, or cloud cards — and cells in the By service type matrix — to filter. Click again to clear. Actionable is Open + Investigating. All / History shows every status. Search the summary.
  3. Open a row for the daily timeline, region breakdown, and the resources that drove the spike. Click a resource to open it in Inventory.
  4. Set status from the table or in bulk. Every status change needs a comment.

Status

Status Meaning
Open Still in the actionable queue.
Investigating Someone is looking at it (comment required).
Resolved Expected or already handled (comment required).
Silenced Hidden from the open queue for 30 days (comment required).

There is no Dismissed status and no auto-silence.

Severity

High, Medium, and Low come from how far the day sat above its baseline. Click a severity cell in the matrix to filter.

When it stays empty

  • Cost has not been refreshed — run Refresh data for Cost.
  • Nothing in the selected period broke its weekday or month-end pattern.
  • Filters hide the rows — clear the matrix, search, and status (or switch off All / History).