DATA OPS

BigQuery row-count anomaly detection with PagerDuty escalation

After each nightly BigQuery load, this compares today's partition row count against the trailing 30-day baseline using a z-score.

CategoryData Ops
Enginesim
Difficultyintermediate
Triggerschedule
Steps5
Setup~15 min

How it runs

The automated pipeline, trigger to output.

  • TriggerNightly cron after ingestion
  • ActionQuery today + trailing 30-day row countsGoogle BigQueryBigQuery
  • LogicCompute z-score and classify anomalies
  • LogicBranch: escalate only on breach
  • OutputOpen PagerDuty incident for on-callPagerDutyPagerDuty

What it does

Detects volume anomalies in freshly loaded BigQuery partitions. It pulls today's row count for each monitored table plus the trailing 30-day daily counts, computes a z-score against that baseline, and decides whether the load is suspiciously small (dropped rows), suspiciously large (duplicate load), or normal. Real anomalies escalate to PagerDuty; everything else stays quiet.

When to use it

Use it when a load "succeeds" but quietly writes the wrong amount of data — a truncated upstream extract or a double-run that doubles a fact table. Pure freshness checks miss these because the timestamp looks fine.

How it works

  1. 1A nightly cron fires after BigQuery ingestion completes.
  2. 2A query returns today's partition count and the trailing 30-day counts per table.
  3. 3A logic step computes the z-score and classifies each table as normal, low, or high.
  4. 4If any table breaches the threshold, an enriched incident payload is built with the expected range and observed count.
  5. 5A PagerDuty incident is opened and routed to the data on-call rotation.

Set it up

What you configure once, before turning it on.

  1. 1
    Connect BigQueryDatasets, queries, schemas.
  2. 2
    Connect PagerDutyIncidents, on-call, escalations.
  3. 3
    Set each agent's modelWe leave models unset so you pick the tier — fast + cheap, or top-quality.
  4. 4
    Tune it to your dataEdit the prompts, filters, and field mappings so it matches how your team works.
  5. 5
    Test, then turn it onRun once against a sample, confirm the output, then enable the trigger.

Run this workflow in your colony.

14-day trial. No DevOps. No Sales call. Provisioned in under a minute.