How do I get AWS cost spike alerts in Slack?

read

Quick answer: Two ways. With AWS alone you wire Cost Anomaly Detection to an SNS topic, then to Slack through Amazon Q Developer. It runs about three times a day, on data that is 12 to 48 hours old. With watchmy.cloud you connect AWS read-only, pick a Slack channel, and we check your spend every hour. Catching single hours needs hourly granularity in Cost Explorer. AWS charges about a cent per resource per day for it.

Cost problems get fixed fast when the alert lands where the engineers are. If your team lives in Slack, an alert sitting in a billing console does nothing.

Why put cost alerts in Slack at all?

Because the person who can fix a spike is an engineer. They roll back the deploy. They kill the runaway job. They delete the environment nobody turned off. And they do not open Cost Explorer on a Tuesday.

An alert in the team channel turns a month-end surprise into a same-day fix. It leaves a record too: the spike, the cause, the fix, one thread.

An email in a busy inbox is not the same thing. A spike is a to-do, not a newsletter.

How do you do it with AWS alone?

AWS has the parts. You assemble them.

1. Create a Cost Anomaly Detection monitor in Cost Management.

2. Create an alert subscription. Choose individual alerts, not a daily summary.

3. Create an SNS topic. Subscribe to it. Confirm the subscription.

4. Set up Amazon Q Developer in chat applications. Authorize Slack. Map the topic to a channel.

5. Set a dollar floor so small moves stay quiet.

6. Come back and re-tune that floor when normal drifts.

It works, and it comes with your AWS account. It is also three services and a wiring job. Nothing in it creates itself. Nothing updates itself.

How fast is that path?

Not fast. AWS says Cost Anomaly Detection runs about three times a day. It reads Cost Explorer, which runs 12 to 48 hours behind. So a spike can hide for a day, sometimes two.

A new monitor needs 24 hours before it detects anything. A service you just started using needs 10 days of history first.

That is fine for a slow drift. It is late for a runaway job.

What does watchmy.cloud do instead?

Connect AWS. Read-only billing access. No keys. No access to what you run. One CloudFormation template, about two minutes.

Send it where work happens. Slack for fast triage. Jira for follow-up. API when you want control.

Stop worrying about it. We watch AWS spend for you, so you don't have to keep checking it.

You pick the Slack channel on Slack's own consent screen. Two rules are already on: one for a day 30% above your own 7-day average, one for an hour at three times your 24-hour average. A single dial tunes both, from 1 (relaxed) to 5 (strict). After that it runs automagically.

We check your spend every hour and post the spike to your channel. The hour-level rule needs hourly granularity turned on in Cost Explorer. AWS bills that at about a cent per resource per day. Without it, you still get the daily checks.

What does the Slack alert say?

Enough to triage without opening anything else:

  • which account it is

  • the value that fired, next to the threshold it crossed

  • how many dollars over it went

  • the services behind it, like "Compute +$30.12 · Databases +$8.00"


Who gets paged when your bill doubles?

Nobody at AWS. That is not a dig. It is how the incentives sit. AWS bills what you use, and a quiet spike is your problem. You find it on the invoice.

Most people search for billing alerts after the incident, not before. A forgotten GPU instance runs about $3,000 a week. A leaked key buys a stranger two days of your compute. Then comes the shock, and the debt to AWS. If nothing has burned yet, you are early. This is a ten-minute job.

How do the two compare?

  • Detection — AWS alone (CAD + SNS + Amazon Q Developer): About 3x a day, on data 12-48 h old. watchmy.cloud: Every hour, once hourly granularity is on.

  • Setup — AWS alone (CAD + SNS + Amazon Q Developer): 3 services, several console steps. watchmy.cloud: Read-only role, about two minutes.

  • Slack message — AWS alone (CAD + SNS + Amazon Q Developer): The SNS payload, relayed. watchmy.cloud: Account, value, dollars over, top services.

  • Other channels — AWS alone (CAD + SNS + Amazon Q Developer): Email; more through SNS plumbing. watchmy.cloud: Jira, GitHub Issues, email, SMS, webhook.

  • Noise control — AWS alone (CAD + SNS + Amazon Q Developer): One dollar-impact threshold. watchmy.cloud: Dial 1-5, cooldowns, per-rule caps, ticket dedup.

  • Who tunes it — AWS alone (CAD + SNS + Amazon Q Developer): You. watchmy.cloud: The baseline moves with your spend.

  • Price — AWS alone (CAD + SNS + Amazon Q Developer): In your AWS bill. watchmy.cloud: Flat $49 a month.

How do you keep the channel quiet?

Noise kills alerting. After the third false alarm, everyone mutes the channel. Four rules help, either way.

  • Set a floor. Alert on dollars that matter, not on every move. Our dial does this. In Cost Anomaly Detection it is the dollar-impact threshold.

  • Use cooldowns. One spike is one alert, not one per hour it lingers.

  • Cap the burst. A flapping rule should throttle itself and leave the others alone. Ours stops at 24 alerts a day, per rule.

  • Deduplicate tickets. The first alert opens the Jira or GitHub issue. Later ones comment on it.


No more AWS bill surprises

No more AWS bill surprises

Try it today

Try it today

How does watchmy.cloud help here?

This is the whole product. We check your AWS spend every hour and route the alert to the channel your team already reads. Rules on from day one. A flat $49 a month. See how it works, or what a real spike looks like in why did my AWS bill suddenly increase.

Watching AWS spend is our full-time job. You focus on your product — and sleep well.

FAQ

Can AWS send cost alerts to Slack without a third-party tool?

Yes. Wire Cost Anomaly Detection to an SNS topic, then connect that topic to Slack through Amazon Q Developer in chat applications. Expect daily-grain detection. It runs about three times a day, on data that is 12 to 48 hours old.

How fast can a Slack cost alert arrive after a spike starts?

With AWS alone, the next day at best. Cost Explorer runs 12 to 48 hours behind, and the detector reads it a few times a day. With watchmy.cloud, we re-check every hour. With hourly granularity on in Cost Explorer, the alert lands about an hour after the spike shows up in the data.

Do I need to install anything in my AWS account?

A read-only IAM role and a notification topic, from one CloudFormation template. No keys. No agents. No Lambda. No access to what you run.

Can the same alert go somewhere other than Slack?

Yes. Slack, Jira, GitHub Issues, email, SMS and webhooks. Pick any combination per alert rule.

What does watchmy.cloud cost?

A flat $49 a month, whatever your bill looks like. No per-account pricing, no percentage of spend.

See it before you connect anything: live demo, no sign-up.

watchmy.cloud
A smoke detector for your AWS bill. Built by engineers who got tired of cost surprises.

watchmy.cloud
A smoke detector for your AWS bill. Built by engineers who got tired of cost surprises.

watchmy.cloud
A smoke detector for your AWS bill. Built by engineers who got tired of cost surprises.