Bedrock knowledge bases with no retrieval activity in 30 days and a dedicated vector store
What does ZopNight detect here?
ZopNight's idle check for Amazon Bedrock knowledge bases needs `Retrieve` or `RetrieveAndGenerate` activity data over 30 days, and AWS publishes no per-knowledge-base retrieval metrics, so no finding is raised today. When one is, the saving is the dedicated OpenSearch Serverless collection's monthly OCU and storage cost.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1606 |
| Category | orphan |
| Severity | medium |
| Metric | none — pure configuration read |
| Threshold | zero retrievals |
| Evaluation window | 30d |
| Source | ZopNight |
| Permissions used | bedrock:ListKnowledgeBases · bedrock:GetKnowledgeBase · aoss:BatchGetCollection |
The cost lives in the vector store, not the knowledge base
A Bedrock knowledge base is a configuration that ties a data source to a vector store. The money is in the vector store. For the common OpenSearch Serverless choice, compute is measured in OpenSearch Compute Units, and OpenSearch Service pricing charges Serverless compute and storage separately. The capacity guide describes each OCU as 6 GiB of memory with matching vCPU.
Knowledge bases get built for pilots and demos, and the collection behind each keeps billing after the assistant is switched off.
Finding knowledge bases and their collections
aws bedrock-agent list-knowledge-bases \ --query 'knowledgeBaseSummaries[].[name,knowledgeBaseId,updatedAt]' --output table
aws bedrock-agent get-knowledge-base --knowledge-base-id KB12345678 \ --query 'knowledgeBase.storageConfiguration'The storage configuration shows the collection ARN. If two knowledge bases share a collection, deleting one will not save anything.
Proof of no use, and a cost to attach
ZopNight looks for retrieval activity, the Retrieve and RetrieveAndGenerate calls, over 30
days. At least one of those signals has to carry real data points before silence is believed;
otherwise every knowledge base would look idle. If either shows any activity, there is no finding.
AWS does not publish per-knowledge-base retrieval metrics in CloudWatch, so neither signal carries
data today and the rule raises no finding yet.
Use the commands above to review knowledge bases by hand.
Next, the knowledge base must have a cost. ZopNight attaches the OpenSearch Serverless
collection’s monthly cost to the knowledge base only when exactly one knowledge base references
that collection, so the same dollars are never counted twice.
Knowledge bases that are never priced
Knowledge bases on Pinecone, Amazon RDS, MongoDB Atlas, Neptune, Redis or S3 vector stores have no collection in ZopNight’s inventory to price, so they are not flagged. A shared collection, or one whose cost is not yet known, leaves the knowledge base at $0, and ZopNight does not show a $0 finding.
Saving the collection’s bill
saving = monthly cost of the dedicated OpenSearch Serverless collectioncost after fix = 0 (knowledge base and collection deleted)Deleting both halves
- Confirm no Bedrock agent or application calls the knowledge base, and disassociate it from any agent.
- Keep the source documents in S3; they are what you would re-ingest.
- Delete the knowledge base with
aws bedrock-agent delete-knowledge-base --knowledge-base-id. - Delete the vector store: for OpenSearch Serverless,
aws opensearchserverless delete-collection --id.