Monitoring overview

Prev Next

Overview

Cost Analyzer provides four monitoring capabilities that work together to give your team continuous visibility over Azure spending. Each capability serves a distinct purpose in the cost governance lifecycle, from setting hard budget limits and projecting future spend, to detecting statistical anomalies and building precise rule-based alerts for specific cost segments.

Business value

  • Catch budget overruns before the billing cycle closes, not after
  • Detect unexpected cost spikes automatically, without scanning reports manually
  • Alert on narrow spend segments, such as a single resource type or a specific tag, that aggregate budgets would miss
  • Route every alert through structured escalation so critical notifications always reach the right person

How it works

Cost Analyzer monitoring operates at the cost management group level. All four capabilities can run simultaneously on the same group, and their alert incidents are managed through a shared incident lifecycle. The Monitoring tab within each cost management group is the central access point for configuring and reviewing all monitoring activity.

Budget planner

Budget planner visualizes historical Azure cost trends and projects future spend based on a planned cost value or a defined growth rate. It supports ML-powered forecasting with upper and lower cost estimates for upcoming months, giving finance teams a forward-looking view of where spend is headed before a threshold is breached.

Use this when: you need to model future spend against a budget target, review historical cost trends in a single view, or produce a cost projection for planning cycles.

Budget planner

Group budget monitoring

Group budget monitoring sets a spending threshold at the cost management group level and alerts you when actual or amortized costs approach or exceed it. You can layer on percentage thresholds (for example, alert at 75% and 90% before the full limit is reached) and enable monthly risk prediction, which projects whether the current spending rate will exceed the budget before the billing period closes.

Alert incidents from group budget monitoring also drive the health indicator on each cost management group in the tree view. A red indicator means the 100% threshold has been reached.

Use this when: you want a simple, group-level spending limit with automatic alerts, or you need an early-warning system that fires before the budget is fully exhausted.

Group budget monitoring

Custom monitoring

Custom monitoring lets you define rule-based monitors that go beyond a fixed group-level budget. Each monitor runs on a configurable interval (Daily, Monthly, or Last 7 days) and applies one or more rules scoped to specific subscriptions, a cost metric (Actual cost or Amortized cost), and optional filters such as resource type, resource group, or tag. Budget limits can be Static (a fixed value) or Dynamic (a defined cost difference that triggers a violation).

Custom monitors are independent of group budget monitoring and can run alongside it on the same cost management group.

Use this when: you need to monitor a specific cost dimension that a group-level budget cannot target, such as virtual machine costs only, costs associated with a particular tag, or spend from a specific subscription within a larger group.

Custom monitoring

Automatic anomaly detection

Automatic anomaly detection identifies unusual cost changes at daily intervals using statistical analysis rather than a fixed threshold. It calculates the standard deviation of the last 30 days of daily cost changes and flags today's change when it exceeds the standard deviation multiplied by a configurable threshold multiplier. This means it reacts to cost behavior that is unusual relative to the group's own history, not just to a dollar value you set in advance.

Anomaly detection activates automatically when a cost management group is created. AI classification and severity scoring run on each detected anomaly to assess whether it is a genuine cost risk or a likely false positive.

Use this when: you want to catch unexpected cost spikes earlier than a budget threshold would, especially in environments where spend varies naturally and a fixed budget limit would either miss real anomalies or generate too much noise.

Automatic anomaly detection

Choosing the right monitoring type

Scenario Recommended type
Set a monthly spending limit for a cost group Group budget monitoring
Get an early warning before the budget is fully exhausted Group budget monitoring with percentage thresholds
Forecast whether current spend will exceed budget this month Budget planner with risk prediction
Monitor costs for a specific resource type, tag, or subscription Custom monitoring
Detect unexpected cost spikes without setting a fixed budget Automatic anomaly detection
Catch both overspend trends and sudden spikes Group budget monitoring + Automatic anomaly detection
Monitor high-risk spend categories alongside a group budget Group budget monitoring + Custom monitoring

Multiple monitoring types can run simultaneously on the same cost management group. There is no conflict between them; each evaluates independently and generates its own alert incidents.

Escalation policies

All alert-generating monitoring types (Group budget, Custom monitoring, and Automatic anomaly detection) route their alerts through escalation policies. An escalation policy defines an ordered sequence of notification rules: when an alert goes unacknowledged, Turbo360 automatically escalates to the next rule in the sequence after a configured time interval, ensuring critical alerts are never silently missed.

A default escalation policy is available out of the box. Custom policies can be created and mapped to individual monitors or group budgets.

Managing escalation policies

Alert incidents

When any monitoring type triggers an alert, Turbo360 creates an alert incident. Incidents move through a shared lifecycle: Open, Acknowledge, Close, and Reopen. You can manage incidents individually or in bulk, view per-channel notification delivery details, and track every state change with a full user action history.

Managing monitoring incidents

Related articles