Linking AWS Cost Anomaly Detection as a source

Let AI connect your sources for you

Skip the manual setup — run this in your project and the wizard auto-detects your databases and APIs and connects them to PostHog.

Learn more
PostHog Wizard hedgehog

Alpha release

This source is currently in alpha. The interface and available tables may change.

The AWS Cost Anomaly Detection connector syncs anomalies, anomaly monitors, anomaly subscriptions, and more into the PostHog data warehouse, so you can analyze them alongside your product data.

Prerequisites

Credentials that can read the data you want to sync. PostHog only reads data, so read access is enough.

Adding a data source

  1. In PostHog, go to the Sources tab of the data pipeline section.
  2. Click + New source and click Link next to this source.
  3. Enter your credentials (see Configuration below) and click Next.
  4. Select the tables you want to sync, choose a sync method and frequency, then click Import.

Once the syncs are complete, you can start querying this data in PostHog.

Sync the cost anomalies AWS detected on your account.

Create an IAM user or role with the ce:GetAnomalies, ce:GetAnomalyMonitors and ce:GetAnomalySubscriptions permissions, then paste its access key ID and secret access key. Add a session token too if you are using temporary credentials.

Cost Explorer has to be enabled once in the AWS console, and it can take up to 24 hours before data is ready. AWS keeps anomalies for 90 days, so that is as far back as a first sync reaches. You only see the monitors and subscriptions created by the account you connect, so connect the management (payer) account for organization-wide coverage.

You'll be asked for:

  • AWS access key ID: for example AKIA....
  • AWS secret access key

Sync modes

Each table can be synced in one of several modes, depending on what the source supports:

  • Webhook (when available) – the source pushes changes to PostHog in real time. Fastest freshness, lowest ongoing cost, and the only mode that reliably captures updates and deletes.
  • Incremental – only new or updated rows are synced on each run, using a cursor field (such as an updated_at timestamp). Cheaper than a full refresh, but deletes aren't captured.
  • Append only – new rows are appended using a cursor field; existing rows are never updated. Ideal for immutable, append-only tables like event logs.
  • Full refresh – the whole table is reloaded on every sync. Use it when a table has no reliable cursor or when you need deletions reflected.

See sync methods for a full explanation of how each mode works and how to choose between them.

All AWS Cost Anomaly Detection tables are full refresh. Each sync replaces the contents of the table.

Configuration

OptionDescription
AWS access key ID
Type: text
Required: True
AWS secret access key
Type: password
Required: True
AWS session token
Type: password
Required: False

Only for temporary credentials. Session tokens expire after a few hours, so scheduled syncs will fail once the token expires. Use a permanent access key (starts with AKIA) for recurring imports.

Supported tables

TableDescriptionSync methodIncremental fieldPrimary key
anomalies

Cost anomalies AWS detected on the account, with their spend impact and root causes. AWS keeps 90 days of anomalies.

Incremental, Full refreshanomaly_end_date—
anomaly_monitors

Cost monitors that inspect the account's spend, with the dimension and specification each one evaluates.

Full refresh——
anomaly_subscriptions

Alert subscriptions attached to the cost monitors, with their subscribers, frequency and alert threshold.

Full refresh——

Troubleshooting

  • If the connection fails with an authorization error, the AWS access key ID is wrong, expired, or has been revoked. Create a new one, then reconnect the source.
  • If a table syncs no rows, the credential may not have access to that data. Check its permissions, then reconnect the source.

If your sync is failing or data looks wrong, see the Data warehouse troubleshooting guide. If that doesn't help, contact support – we're happy to help.

Still have questions?

Was this page useful?