Cloud Log Anomaly Detector
Every 10 minutes: measure cloud log volume, detect spikes (>2x baseline), LLM analyzes top errors and likely cause — alert to #log-alerts.
Overview
**What it does**: Schedule (every 10 min) → query cloud logs (AWS CloudWatch, GCP Cloud Logging, Azure Monitor) for error rate/volume → code detects anomaly: current > 2x baseline? → IF spike → fetch top errors + services generating them → LLM diagnoses (which service failing, error type, severity: cascade, new bug, traffic spike) → Slack to #log-alerts. **Setup (4 steps)**: 1. Connect cloud logs: AWS CloudWatch, GCP Cloud Logging, Azure Monitor (API endpoint + credentials) 2. Set baseline: measure normal error rate (automatic rolling 7-day avg) 3. Configure spike threshold: multiplier (default 2x = 100% increase) 4. Set Slack channel: #log-alerts **Apps/nodes**: Schedule, HTTP request (logs API), code node (anomaly math), Claude/OpenAI (diagnosis), Slack. **Credentials required**: Cloud logs API key, OpenAI account, Slack workspace. **Difficulty**: Easy | **Setup time**: 6 minutes. **Business outcome**: Catches error cascades, service issues, traffic spikes instantly → incident response ↑ faster, MTTR ↓ 50%.
What's included
Inside this workflow
Quickstart
- 01
Download the JSON
With an active Library Pass, download the workflow file right from this page or your dashboard.
- 02
Import into n8n
Choose Import from File and select the downloaded JSON. The full agent graph appears, ready to configure.
- 03
Plug in credentials
Each integration node prompts for credentials on first run. The setup guide lists every credential the agent expects.
- 04
Activate and test
Run once with sample input, confirm the expected output, then flip the activate toggle.
Frequently Asked Questions
How do I import this workflow into n8n?
What credentials do I need to provide?
Are the credentials included in the JSON file?
Can I edit or customize the workflow after importing?
What n8n version is required?
What if something breaks after I import it?
Can I use this workflow for my customers or business?
Will the workflow receive updates?
Do I need n8n Pro or a paid plan?
Can I ask for a custom workflow?
Reviews (0)
No reviews yet. Be the first.
Sign in to leave a review.
Included with any pass
This agent — and every other in the library — comes with a Library Pass. One pass, the whole catalog.
Get a Library Pass- Every agent in the library
- All new releases while active
- Unlimited downloads
- Commercial-use license
- Priority email support
- 30-day money-back guarantee
More in Reliability
Batch Job Failure Watchdog
Monitor scheduled cloud batch jobs; on failure, LLM summarizes what failed, when it last ran, and recovery steps — escalate to #batch-ops.
SSL Certificate & Domain Expiry Monitor
Daily: scan all domains and certificates across accounts; alert 60/30/7 days before expiry to prevent outages.
Cloud Availability SLO Monitor
Hourly check: if availability burn exceeds 50%, escalate with hours until SLO breach, affected services, and remediation steps.