Skip to main content
resource · aws

AWS Data Transfer (Account)

live rule families
2
schedulable
no
category
networking-services

Does ZopNight manage AWS Data Transfer (Account)?

Data transfer is metered per GB along every path traffic takes: out to the internet, between regions, and across availability zones. None of it appears as a resource in any console. ZopNight no longer splits transfer into its own row: the dollars stay inside each service's ordinary billing rows, and the two transfer rules (RC-065, RC-178) are retired.

At a glance

AWS Data Transfer (Account) coverage facts.
Field Value
Scheduling notesaccount-level cost analysis only.

Data transfer covers the per-GB charges AWS applies to traffic leaving regions, crossing availability zones, and egressing to the internet. It is one of the least visible line items on an AWS bill and frequently a large one.

A meter with no resource attached

Every other page in this directory describes a thing you can list in a console. Data transfer is different: it is a family of per-GB usage types stamped onto other resources’ traffic. Internet egress bills per GB out. Inter-region traffic bills per GB in each direction of the pair. Cross-AZ traffic inside a region bills per GB on both the sending and receiving side. Inbound from the internet is free, which lures architectures into assuming traffic is generally free. It is not, once it moves laterally.

Not split out by ZopNight today

ZopNight used to run a dedicated account-level provider for this domain, with cross-AZ and cross-region transfer recommendations (RC-065, RC-178) on top. The provider and both rules are retired, so transfer dollars now stay inside the ordinary per-service billing rows rather than appearing as separate egress, inter-region and cross-AZ series. Locating hot spots is a Cost Explorer job (see below), and it is the prerequisite for any fix, because transfer problems are architectural, not operational.

The classic transfer traps

Cross-AZ chatter between microservices that could be zone-affine; databases and their replicas placed in different zones from the applications hammering them; NAT gateways in one AZ serving subnets in another, stacking cross-AZ rates onto NAT processing rates; S3 access from another region that a same-region bucket or replication setup would make free; and logging pipelines shipping every byte to a third-party SaaS over the public internet at full egress rates.

Following the bytes in Cost Explorer

Cost Explorer, grouped by usage type and filtered to transfer-related types, is the native way to see this spend; the CUR gives line-level attribution to the resources that generated it. From there, VPC Flow Logs identify the talkative pairs, which is where the actual engineering work starts.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·