Billed CloudWatch dashboards nobody has opened in 45 days
What does ZopNight detect here?
ZopNight flags a CloudWatch dashboard whose most recent `GetDashboard` view is at least 45 days old and which carries a real monthly charge. CloudWatch includes 3 custom dashboards of up to 50 metrics each per month free, so only dashboards beyond that allowance are billed, and deleting an unviewed one recovers its full fee.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-094 |
| Category | orphan |
| Severity | low |
| Metric | none — pure configuration read |
| Threshold | last viewed 45+ days ago |
| Evaluation window | 45d |
| Source | ZopNight |
| Permissions used | cloudwatch:ListDashboards · cloudtrail:LookupEvents |
Where it applies
Dashboards past the free three are billed monthly
CloudWatch pricing includes 3 custom dashboards that reference up to 50 metrics each per month in the free tier, and automatic dashboards are free. Every custom dashboard beyond that is charged per dashboard per month. Teams build a dashboard for a launch, an incident or a quarterly review, and they accumulate.
A dashboard nobody opens is paying for a view no one takes.
Finding out when a dashboard was last opened
CloudWatch does not store a “last viewed” field. list-dashboards returns LastModified, which
changes only when someone edits the dashboard. Views show up as GetDashboard API calls, which
CloudTrail records
along with calls made from the console. CloudTrail’s event history keeps 90 days of management
events per Region:
aws cloudwatch list-dashboards \ --query 'DashboardEntries[].[DashboardName,LastModified]' --output table
aws cloudtrail lookup-events \ --lookup-attributes AttributeKey=EventName,AttributeValue=GetDashboard \ --query 'Events[].[EventTime,Username]' --output tableCompare the dashboard names in the event records with the full list.
The 45-day rule and the view record
ZopNight reads the same kind of view events, keeps the latest one per dashboard, and measures the days since. A dashboard whose last view is at least 45 days old, and whose monthly cost is above zero, gets a finding. The saving is the whole dashboard fee.
Dashboards that are not flagged
Most dashboards cost nothing because they fall inside the free allowance, and a $0 dashboard is never flagged. A dashboard with no captured view at all is also left alone: ZopNight looks back over roughly the last 90 days of events, so a dashboard untouched for longer than that has no view to measure from, and without permission to read the events there is no signal either. In practice this means findings cover dashboards last opened between about 45 and 90 days ago; long-abandoned ones need the manual check above or a trail with longer retention.
One dashboard fee per finding
saving = monthly charge for the dashboardcost after fix = 0Retiring stale dashboards
- Check the view history above and ask the dashboard’s owner whether anyone still relies on it.
- Export the body with
aws cloudwatch get-dashboard --dashboard-nameif you may want it back. - Delete it with
aws cloudwatch delete-dashboards --dashboard-names. - Consolidate related dashboards so the account stays near the free allowance.