Anomaly detection Daily by default, hourly available

Databricks anomaly detection with the evidence attached.

LakeSentry runs seven anomaly detectors over your Databricks spend: cost spikes, duration anomalies, failure‑rate spikes, warehouse and serving spend changes, budget risk, and declining attribution. Every detection includes its baseline, z-score, and dollar delta, so you can judge an alert in seconds instead of reconstructing it in SQL.

Start Free

Read-only by default. Write access only if you choose to execute actions.

app.lakesentry.io/insights
Anomaly Critical 2 hours ago
Cost spike detected
etl_daily_ingest · Jobs compute · ws-prod-01
Baseline (30d mean) $1,240/day
Current $3,964/day
Z-score 4.1
Delta +$2,724/day
Multiplier 3.2× baseline
Baseline runs 341
Daily cost · last 14 days
View in Cost Changes → Open workload →
Anomaly Medium 1 day ago
Warehouse spend spike
analytics_warehouse · +$1,180 over 30 days

What a Budget Alert Doesn’t Tell You

Databricks budgets and alerts work as designed: set a threshold, get an email when spend crosses it. If your question is “did we exceed the number”, they answer it.

The question that follows is “what changed”. A threshold alert carries no baseline and no culprit. Was it one job’s retry loop, a warehouse that scaled up and stayed there, or a genuinely bigger workload? Someone opens a notebook and starts digging. That investigation is the real cost of every alert.

  • Thresholds fire on the total, not the change; a slow 40% drift never triggers them.
  • No baseline means no sense of “unusual”; every alert starts from zero context.
  • An alert names the budget it crossed, not the workload that moved.

How LakeSentry Detects Cost Anomalies

Statistical detectors over a normalized ledger, tuned so smaller environments don’t drown in noise.

Seven detectors, one ledger

Cost spikes, duration anomalies, failure-rate spikes, warehouse spend spikes, serving spikes, budget risk, and attribution decline. Detection runs daily by default; hourly extraction is available when you need faster signal.

Evidence in the alert

Each detection shows the baseline it was judged against, the z-score, and the dollar delta. Detectors carry minimum-impact floors, so a $6 notebook doubling its cost doesn’t page anyone.

From alert to answer

Every insight links into Cost Changes, the Cost Explorer, and the workload that produced it. The path from “something moved” to “this job, this cluster, this team” is one click.

Budget Alerts vs Anomaly Detection

Both have a place. One tells you a number was crossed; the other tells you what moved.

Databricks budgets & alerts LakeSentry
Trigger Fixed threshold you set and maintain Statistical baseline per workload, updated as behavior changes
Context in the alert The amount and the budget name Baseline, deviation, dollar delta, and the workload behind it
Noise control Whatever thresholds you keep tuned Minimum baselines and dollar deltas built into each detector
Coverage Spend totals Spend, duration, failure rate, serving patterns, budget risk, attribution share
Investigation Manual, from system tables Linked drill-down into Cost Explorer and the affected workload

The detectors run in every tier: Free includes insight summaries across unlimited workspaces; Standard adds full insight details.

Free

$0€0

Standard

$499€499/mo

Pro

$849€849/mo

Full pricing

No per-DBU tax. No per-workspace fees. Paid tiers billed annually.

Frequently Asked Questions

What counts as a cost anomaly in Databricks?
Spend that breaks its own pattern: a job whose cost jumps well past its baseline, a warehouse whose spend moves outside its normal range, serving costs shifting week over week. LakeSentry compares each workload with its own history, not a global average.
How does LakeSentry avoid false alarms?
Every detector has minimum-impact floors: small baselines and small dollar deltas don’t fire, and constant, near-zero-variance data isn’t flagged. The target is a feed of alerts worth reading.
Is detection real-time?
Daily by default, with hourly extraction available. For cost anomalies that’s the practical window: billing data itself lands with a lag, and a daily signal with evidence beats an instant one without it.
Does LakeSentry need write access to detect anomalies?
No. Detection runs entirely on a read-only service principal reading system tables. Write access matters only if you later choose to execute recommendations through LakeSentry, and that path is admin-gated, with every approval and result in an audit log.
Can it flag a budget overrun before it happens?
Yes. The budget-risk detector projects current spend against your budget and flags a likely overage while the month is still in progress. That’s the difference between hearing about an overrun mid-month and reading about it on the invoice.

See it in your own environment.

The free tier covers unlimited workspaces with three months of history. No card required.

Start Free