Skip to content

aws.cloudwatch.describe_anomaly_detectors

Example SQL Queries

SELECT * FROM
aws.cloudwatch.describe_anomaly_detectors;

Description

Lists the anomaly detection models that you have created in your account. For single metric anomaly detectors, you can list all of the models in your account or filter the results to only the models that are related to a certain namespace, metric name, or metric dimension. For metric math anomaly detectors, you can list them by adding METRIC_MATH to the AnomalyDetectorTypes array. This will return all metric math anomaly detectors in your account.

Table Definition

Column NameColumn Data Type
anomaly_detector_types Input Column

The anomaly detector types to request when using DescribeAnomalyDetectorsInput. If empty, defaults to SINGLE_METRIC.

VARCHAR[]
Show child fields
anomaly_detector_types[]
dimensions Input Column

The metric dimensions associated with the anomaly detection model.

STRUCT(
"name" VARCHAR,
"value" VARCHAR
)[]
Show child fields
dimensions[]
Show child fields
dimensions[].name

The name of the dimension. Dimension names must contain only ASCII characters, must include at least one non-whitespace character, and cannot start with a colon (:). ASCII control characters are not supported as part of dimension names.

dimensions[].value

The value of the dimension. Dimension values must contain only ASCII characters and must include at least one non-whitespace character. ASCII control characters are not supported as part of dimension values.

metric_name Input Column

The name of the metric associated with the anomaly detection model.

VARCHAR
namespace Input Column

The namespace of the metric associated with the anomaly detection model.

VARCHAR
_aws_profile Input Column

The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role.

STRUCT(
"type" VARCHAR,
"name" VARCHAR,
"account_id" VARCHAR,
"via_profile_name" VARCHAR,
"assumed_role_arn" VARCHAR,
"organization" STRUCT(
"account_name" VARCHAR,
"id" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[],
"master_account" STRUCT(
"id" VARCHAR,
"email" VARCHAR
),
"parents" STRUCT(
"type" VARCHAR,
"id" VARCHAR,
"name" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[]
)[]
)
)
Show child fields
_aws_profile.account_id

The AWS account id

_aws_profile.assumed_role_arn

The ARN of the assumed role

_aws_profile.name

The unique name of the profile.

_aws_profile.organization

Information about this profile's membership in the AWS organization.

Show child fields
_aws_profile.organization.account_name

The name of account speciifed by the organization

_aws_profile.organization.id

The organization id

_aws_profile.organization.master_account
Show child fields
_aws_profile.organization.master_account.email

The organization master account email address

_aws_profile.organization.master_account.id

The organization master account id

_aws_profile.organization.parents[]
Show child fields
_aws_profile.organization.parents[].id

The id of the parent

_aws_profile.organization.parents[].name

The name of the parent

_aws_profile.organization.parents[].tags[]
Show child fields
_aws_profile.organization.parents[].tags[].key
_aws_profile.organization.parents[].tags[].value
_aws_profile.organization.parents[].type

The type of parent can be an organization unit or a root

_aws_profile.organization.tags[]
Show child fields
_aws_profile.organization.tags[].key
_aws_profile.organization.tags[].value
_aws_profile.type

The type of profile, either 'credentials' or 'assumed_role'

_aws_profile.via_profile_name

This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.

configuration

The configuration specifies details about how the anomaly detection model is to be trained, including time ranges to exclude from use for training the model, and the time zone to use for the metric.

STRUCT(
"excluded_time_ranges" STRUCT(
"start_time" TIMESTAMP_S,
"end_time" TIMESTAMP_S
)[],
"metric_timezone" VARCHAR
)
Show child fields
configuration.excluded_time_ranges[]
Show child fields
configuration.excluded_time_ranges[].end_time

The end time of the range to exclude. The format is yyyy-MM-dd'T'HH:mm:ss. For example, 2019-07-01T23:59:59.

configuration.excluded_time_ranges[].start_time

The start time of the range to exclude. The format is yyyy-MM-dd'T'HH:mm:ss. For example, 2019-07-01T23:59:59.

configuration.metric_timezone

The time zone to use for the metric. This is useful to enable the model to automatically account for daylight savings time changes if the metric is sensitive to such time changes.

To specify a time zone, use the name of the time zone as specified in the standard tz database. For more information, see tz database.

metric_characteristics

This object includes parameters that you can use to provide information about your metric to CloudWatch to help it build more accurate anomaly detection models. Currently, it includes the PeriodicSpikes parameter.

STRUCT(
"periodic_spikes" BOOLEAN
)
Show child fields
metric_characteristics.periodic_spikes

Set this parameter to true if values for this metric consistently include spikes that should not be considered to be anomalies. With this set to true, CloudWatch will expect to see spikes that occurred consistently during the model training period, and won't flag future similar spikes as anomalies.

metric_math_anomaly_detector

The CloudWatch metric math expression for this anomaly detector.

STRUCT(
"metric_data_queries" STRUCT(
"id" VARCHAR,
"metric_stat" STRUCT(
"metric" STRUCT(
"namespace" VARCHAR,
"metric_name" VARCHAR,
"dimensions" STRUCT(
"name" VARCHAR,
"value" VARCHAR
)[]
),
"period" BIGINT,
"stat" VARCHAR,
"unit" VARCHAR
),
"expression" VARCHAR,
"label" VARCHAR,
"return_data" BOOLEAN,
"period" BIGINT,
"account_id" VARCHAR
)[]
)
Show child fields
metric_math_anomaly_detector.metric_data_queries[]
Show child fields
metric_math_anomaly_detector.metric_data_queries[].account_id

The ID of the account where the metrics are located.

If you are performing a GetMetricData operation in a monitoring account, use this to specify which account to retrieve this metric from.

If you are performing a PutMetricAlarm operation, use this to specify which account contains the metric that the alarm is watching.

metric_math_anomaly_detector.metric_data_queries[].expression

This field can contain either a Metrics Insights query, or a metric math expression to be performed on the returned data. For more information about Metrics Insights queries, see Metrics Insights query components and syntax in the Amazon CloudWatch User Guide.

A math expression can use the Id of the other metrics or queries to refer to those metrics, and can also use the Id of other expressions to use the result of those expressions. For more information about metric math expressions, see Metric Math Syntax and Functions in the Amazon CloudWatch User Guide.

Within each MetricDataQuery object, you must specify either Expression or MetricStat but not both.

metric_math_anomaly_detector.metric_data_queries[].id

A short name used to tie this object to the results in the response. This name must be unique within a single call to GetMetricData. If you are performing math expressions on this set of data, this name represents that data and can serve as a variable in the mathematical expression. The valid characters are letters, numbers, and underscore. The first character must be a lowercase letter.

metric_math_anomaly_detector.metric_data_queries[].label

A human-readable label for this metric or expression. This is especially useful if this is an expression, so that you know what the value represents. If the metric or expression is shown in a CloudWatch dashboard widget, the label is shown. If Label is omitted, CloudWatch generates a default.

You can put dynamic expressions into a label, so that it is more descriptive. For more information, see Using Dynamic Labels.

metric_math_anomaly_detector.metric_data_queries[].metric_stat

The metric to be returned, along with statistics, period, and units. Use this parameter only if this object is retrieving a metric and not performing a math expression on returned data.

Within one MetricDataQuery object, you must specify either Expression or MetricStat but not both.

Show child fields
metric_math_anomaly_detector.metric_data_queries[].metric_stat.metric

The metric to return, including the metric name, namespace, and dimensions.

Show child fields
metric_math_anomaly_detector.metric_data_queries[].metric_stat.metric.dimensions[]
Show child fields
metric_math_anomaly_detector.metric_data_queries[].metric_stat.metric.dimensions[].name

The name of the dimension. Dimension names must contain only ASCII characters, must include at least one non-whitespace character, and cannot start with a colon (:). ASCII control characters are not supported as part of dimension names.

metric_math_anomaly_detector.metric_data_queries[].metric_stat.metric.dimensions[].value

The value of the dimension. Dimension values must contain only ASCII characters and must include at least one non-whitespace character. ASCII control characters are not supported as part of dimension values.

metric_math_anomaly_detector.metric_data_queries[].metric_stat.metric.metric_name

The name of the metric. This is a required field.

metric_math_anomaly_detector.metric_data_queries[].metric_stat.metric.namespace

The namespace of the metric.

metric_math_anomaly_detector.metric_data_queries[].metric_stat.period

The granularity, in seconds, of the returned data points. For metrics with regular resolution, a period can be as short as one minute (60 seconds) and must be a multiple of 60. For high-resolution metrics that are collected at intervals of less than one minute, the period can be 1, 5, 10, 30, 60, or any multiple of 60. High-resolution metrics are those metrics stored by a PutMetricData call that includes a StorageResolution of 1 second.

If the StartTime parameter specifies a time stamp that is greater than 3 hours ago, you must specify the period as follows or no data points in that time range is returned:

  • Start time between 3 hours and 15 days ago - Use a multiple of 60 seconds (1 minute).

  • Start time between 15 and 63 days ago - Use a multiple of 300 seconds (5 minutes).

  • Start time greater than 63 days ago - Use a multiple of 3600 seconds (1 hour).

metric_math_anomaly_detector.metric_data_queries[].metric_stat.stat

The statistic to return. It can include any CloudWatch statistic or extended statistic.

metric_math_anomaly_detector.metric_data_queries[].metric_stat.unit

When you are using a Put operation, this defines what unit you want to use when storing the metric.

In a Get operation, if you omit Unit then all data that was collected with any unit is returned, along with the corresponding units that were specified when the data was reported to CloudWatch. If you specify a unit, the operation returns only data that was collected with that unit specified. If you specify a unit that does not match the data collected, the results of the operation are null. CloudWatch does not perform unit conversions.

metric_math_anomaly_detector.metric_data_queries[].period

The granularity, in seconds, of the returned data points. For metrics with regular resolution, a period can be as short as one minute (60 seconds) and must be a multiple of 60. For high-resolution metrics that are collected at intervals of less than one minute, the period can be 1, 5, 10, 30, 60, or any multiple of 60. High-resolution metrics are those metrics stored by a PutMetricData operation that includes a StorageResolution of 1 second.

metric_math_anomaly_detector.metric_data_queries[].return_data

When used in GetMetricData, this option indicates whether to return the timestamps and raw data values of this metric. If you are performing this call just to do math expressions and do not also need the raw data returned, you can specify false. If you omit this, the default of true is used.

When used in PutMetricAlarm, specify true for the one expression result to use as the alarm. For all other metrics and expressions in the same PutMetricAlarm operation, specify ReturnData as False.

single_metric_anomaly_detector

The CloudWatch metric and statistic for this anomaly detector.

STRUCT(
"account_id" VARCHAR,
"namespace" VARCHAR,
"metric_name" VARCHAR,
"dimensions" STRUCT(
"name" VARCHAR,
"value" VARCHAR
)[],
"stat" VARCHAR
)
Show child fields
single_metric_anomaly_detector.account_id

If the CloudWatch metric that provides the time series that the anomaly detector uses as input is in another account, specify that account ID here. If you omit this parameter, the current account is used.

single_metric_anomaly_detector.dimensions[]
Show child fields
single_metric_anomaly_detector.dimensions[].name

The name of the dimension. Dimension names must contain only ASCII characters, must include at least one non-whitespace character, and cannot start with a colon (:). ASCII control characters are not supported as part of dimension names.

single_metric_anomaly_detector.dimensions[].value

The value of the dimension. Dimension values must contain only ASCII characters and must include at least one non-whitespace character. ASCII control characters are not supported as part of dimension values.

single_metric_anomaly_detector.metric_name

The name of the metric to create the anomaly detection model for.

single_metric_anomaly_detector.namespace

The namespace of the metric to create the anomaly detection model for.

single_metric_anomaly_detector.stat

The statistic to use for the metric and anomaly detection model.

stat

The statistic associated with the anomaly detection model.

VARCHAR
state_value

The current status of the anomaly detector's training.

VARCHAR