AWS Security ChangesHomeSearch

AWS AmazonCloudWatch: Document anomaly detection alarm feedback feature

Service: AmazonCloudWatch · 2026-09-27 · Documentation low

File: AmazonCloudWatch/latest/monitoring/Create_Anomaly_Detection_Alarm.md

Summary

Adds a new section describing how to submit feedback (Correct, False alarm, Missed) on CloudWatch anomaly detection alarms to improve model accuracy, including the SubmitAlarmFeedback API note.

Security assessment

The change documents a monitoring/accuracy tuning feature for anomaly detection alarms; it does not address a vulnerability, credential, or access control concern.

Evidence

+## Improving anomaly detection alarm accuracy with feedback

Diff

diff --git a/AmazonCloudWatch/latest/monitoring/Create_Anomaly_Detection_Alarm.md b/AmazonCloudWatch/latest/monitoring/Create_Anomaly_Detection_Alarm.md
index b8af246f8..0be02ec58 100644
--- a//AmazonCloudWatch/latest/monitoring/Create_Anomaly_Detection_Alarm.md
+++ b//AmazonCloudWatch/latest/monitoring/Create_Anomaly_Detection_Alarm.md
@@ -7 +7 @@
-Editing an anomaly detection modelDeleting an anomaly detection model
+Editing an anomaly detection modelDeleting an anomaly detection modelImproving anomaly detection alarm accuracy with feedback
@@ -176,0 +177,68 @@ Using anomaly detection for an alarm accrues charges. As a best practice, if you
+## Improving anomaly detection alarm accuracy with feedback
+
+After you create an anomaly detection alarm, you can provide feedback to help CloudWatch improve the accuracy of the anomaly detection model. CloudWatch uses your feedback to adjust how the model learns from your metric's behavior, which can result in more accurate anomaly detection bands over time.
+
+You can provide feedback when you notice that:
+
+  * The alarm triggered correctly, and you want to confirm that the detection was accurate.
+
+  * The alarm triggered, but the metric behavior was actually normal (a false alarm).
+
+  * The alarm did not trigger, but the metric behavior was anomalous (a missed detection).
+
+
+
+
+###### To submit feedback on an anomaly detection alarm
+
+  1. Open the CloudWatch console at [https://console.aws.amazon.com/cloudwatch/](https://console.aws.amazon.com/cloudwatch/).
+
+  2. In the navigation pane, choose **Alarms**.
+
+  3. Choose the name of the anomaly detection alarm that you want to provide feedback for.
+
+  4. Choose the **Improve this alarm** button.
+
+  5. In the feedback dialog box, specify a **Start time** and **End time** for the time range that your feedback applies to. This should cover the period where you observed the alarm behavior you want to report.
+
+  6. For **Feedback type** , choose one of the following:
+
+     * **Correct** – The alarm correctly detected an anomaly (or correctly did not trigger). This confirms that the model is performing well for this time range. No model adjustments are made.
+
+     * **False alarm** – The alarm triggered, but the metric behavior was actually normal. CloudWatch adjusts the anomaly detection model to reduce false positives.
+
+     * **Missed** – The alarm did not trigger, but the metric behavior was anomalous and should have been detected. CloudWatch adjusts the anomaly detection model to improve sensitivity.
+
+  7. For **Reason** , choose the reason that best describes why the alarm behavior was incorrect:
+
+     * **Bands learning too fast** – The anomaly detection bands are adapting too quickly to recent changes in metric behavior, treating new patterns as normal too soon.
+
+     * **Bands learning too slow** – The anomaly detection bands are not adapting quickly enough to legitimate changes in metric behavior.
+
+     * **Bands too wide** – The expected range of normal values is too broad, causing the alarm to miss anomalies.
+
+     * **Bands too narrow** – The expected range of normal values is too tight, causing the alarm to trigger on normal metric variations.
+
+     * **Band level off** – The anomaly detection bands are not aligned with the expected baseline level of the metric.
+
+     * **Planned deployment** – The alarm fired due to a planned deployment or change.
+
+     * **Scaling event** – The alarm fired due to an expected scaling event (such as auto-scaling).
+
+     * **Other** – The alarm behavior was incorrect for a reason not listed above.
+
+  8. Choose **Submit**.
+
+
+
+
+CloudWatch processes your feedback and adjusts the anomaly detection model accordingly. For false alarm and missed feedback, CloudWatch automatically tunes the model's learning rate or band width based on the reason that you provide.
+
+###### Note
+
+You can submit feedback multiple times for different time ranges. Each piece of feedback is processed independently and contributes to improving the model's accuracy over time.
+
+###### Note
+
+When you submit feedback, the CloudWatch console calls the `SubmitAlarmFeedback` API on your behalf. This API is used by the CloudWatch console only and is not intended to be called directly.
+