AWS Config rules that have never run a single evaluation
What does ZopNight detect here?
ZopNight flags an AWS Config rule whose `FirstEvaluationStarted` flag from `config:DescribeConfigRuleEvaluationStatus` is false, meaning Config has never evaluated any resource against it. Rule evaluations bill at $0.001 each for the first 100,000, so an idle rule costs about nothing; the finding is a $0 compliance item because the control it represents is not actually running.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-199 |
| Category | compliance |
| Severity | low |
| Metric | none — pure configuration read |
| Threshold | FirstEvaluationStarted = false |
| Source | ZopNight |
| Permissions used | config:DescribeConfigRules · config:DescribeConfigRuleEvaluationStatus |
Where it applies
A rule that exists but checks nothing
A Config rule in the console looks like a control is in place. Whether it has ever done anything is
a separate question, answered by FirstEvaluationStarted, which the
CLI reference
defines as whether Config has evaluated your resources against the rule at least once. A rule that
never started is a silent gap: auditors see it listed, but no resource has ever been marked
compliant or non-compliant by it.
Finding rules that never evaluated
aws configservice describe-config-rule-evaluation-status \ --query 'ConfigRulesEvaluationStatus[?FirstEvaluationStarted==`false`].[ConfigRuleName,FirstActivatedTime,LastErrorCode]' \ --output tableThen look at the rule’s scope to see what it is supposed to target:
aws configservice describe-config-rules --config-rule-names RULE_NAME \ --query 'ConfigRules[].[ConfigRuleName,ConfigRuleState,Scope]'When a never-evaluated rule is reported
ZopNight combines the rule list with each rule’s evaluation status and marks a rule as unused when its first evaluation has not started. The finding appears only when that mark is present and true. If the evaluation status could not be read for a rule, it is left out.
When ZopNight does not report the rule
A rule that has evaluated at least once is never flagged here, even if it now reports zero
resources. Rules whose evaluations fail with errors after a first run are also out of scope; check
LastErrorCode and LastErrorMessage in the same output for those.
Why the finding is priced at $0
AWS Config pricing bills per rule evaluation, and its examples price the first 100,000 evaluations at $0.001 each. A rule with no evaluations has cost essentially nothing, so ZopNight does not present deletion as a saving. The finding is filed as compliance because a control that never runs is worse than no control: it gives false assurance.
Repairing or removing the rule
- Review the rule’s scope and resource type filter; a filter for a type or tag that no resource in this account and Region has is the usual cause.
- Confirm the configuration recorder is recording the resource types the rule targets. See AWS Config Recorder Not Enabled.
- Fix the scope and trigger an evaluation with
aws configservice start-config-rules-evaluation --config-rule-names RULE_NAME. - Delete the rule if the resource type is not used in this account.