Databricks anomaly detection with the evidence attached.
LakeSentry runs seven anomaly detectors over your Databricks spend: cost spikes, duration anomalies, failure‑rate spikes, warehouse and serving spend changes, budget risk, and declining attribution. Every detection includes its baseline, z-score, and dollar delta, so you can judge an alert in seconds instead of reconstructing it in SQL.
Read-only by default. Write access only if you choose to execute actions.
What a Budget Alert Doesn’t Tell You
Databricks budgets and alerts work as designed: set a threshold, get an email when spend crosses it. If your question is “did we exceed the number”, they answer it.
The question that follows is “what changed”. A threshold alert carries no baseline and no culprit. Was it one job’s retry loop, a warehouse that scaled up and stayed there, or a genuinely bigger workload? Someone opens a notebook and starts digging. That investigation is the real cost of every alert.
- Thresholds fire on the total, not the change; a slow 40% drift never triggers them.
- No baseline means no sense of “unusual”; every alert starts from zero context.
- An alert names the budget it crossed, not the workload that moved.
How LakeSentry Detects Cost Anomalies
Statistical detectors over a normalized ledger, tuned so smaller environments don’t drown in noise.
Seven detectors, one ledger
Cost spikes, duration anomalies, failure-rate spikes, warehouse spend spikes, serving spikes, budget risk, and attribution decline. Detection runs daily by default; hourly extraction is available when you need faster signal.
Evidence in the alert
Each detection shows the baseline it was judged against, the z-score, and the dollar delta. Detectors carry minimum-impact floors, so a $6 notebook doubling its cost doesn’t page anyone.
From alert to answer
Every insight links into Cost Changes, the Cost Explorer, and the workload that produced it. The path from “something moved” to “this job, this cluster, this team” is one click.
Budget Alerts vs Anomaly Detection
Both have a place. One tells you a number was crossed; the other tells you what moved.
| Databricks budgets & alerts | LakeSentry | |
|---|---|---|
| Trigger | Fixed threshold you set and maintain | Statistical baseline per workload, updated as behavior changes |
| Context in the alert | The amount and the budget name | Baseline, deviation, dollar delta, and the workload behind it |
| Noise control | Whatever thresholds you keep tuned | Minimum baselines and dollar deltas built into each detector |
| Coverage | Spend totals | Spend, duration, failure rate, serving patterns, budget risk, attribution share |
| Investigation | Manual, from system tables | Linked drill-down into Cost Explorer and the affected workload |
Go Deeper
The mechanics live in the docs; the reasoning lives on the blog.
Anomaly detection in the docs
Detector types, thresholds, and how evidence is computed.
7 reasons Databricks spend changes
The diagnostic checklist behind most anomalies, from DBU multipliers to retry storms.
Databricks native cost tools, compared
Where budgets and alerts stop, and what an intelligence layer adds.
The detectors run in every tier: Free includes insight summaries across unlimited workspaces; Standard adds full insight details.
Free
$0€0
Standard
$499€499/mo
Pro
$849€849/mo
No per-DBU tax. No per-workspace fees. Paid tiers billed annually.
Frequently Asked Questions
What counts as a cost anomaly in Databricks?
How does LakeSentry avoid false alarms?
Is detection real-time?
Does LakeSentry need write access to detect anomalies?
Can it flag a budget overrun before it happens?
See it in your own environment.
The free tier covers unlimited workspaces with three months of history. No card required.