evaluationDate | string | ISO 8601 date on which the anomaly was detected. |
costType | string | "ActualCost" or "AmortizedCost". |
scopeType | string | "subscription", "service", or "resource". |
scopeId | string | The scope identifier — subscription GUID, service name, or resource ID. |
severity | string | "high" or "medium". |
currentAmount | number | Actual spend on the evaluation date. |
baselineMedian | number | Seasonal median from matching-weekday history. |
absoluteChange | number | currentAmount − baselineMedian. |
percentChange | number | Percentage deviation from the baseline median. |
currency | string | ISO 4217 currency code. |
baselinePoints | integer | Number of data points used to compute the baseline. |
kScore | number | Normalized deviation score (multiples of MAD above the median). |
reason | string | Human-readable explanation of the anomaly. |
reviewStatus | string | Investigation lifecycle state: new, investigating, acknowledged, or resolved. |
methodVersion | string | Version token of the anomaly detection algorithm. |