Skip to main content
orphan · aws

Billed CloudWatch dashboards nobody has opened in 45 days

resource types
1
rule IDs covered
1
severity
low

What does ZopNight detect here?

ZopNight flags a CloudWatch dashboard whose most recent `GetDashboard` view is at least 45 days old and which carries a real monthly charge. CloudWatch includes 3 custom dashboards of up to 50 metrics each per month free, so only dashboards beyond that allowance are billed, and deleting an unviewed one recovers its full fee.

Signal and threshold

How ZopNight evaluates Billed CloudWatch dashboards nobody has opened in 45 days.
Field Value
Rule IDsRC-094
Categoryorphan
Severitylow
Metricnone — pure configuration read
Thresholdlast viewed 45+ days ago
Evaluation window45d
SourceZopNight
Permissions usedcloudwatch:ListDashboards · cloudtrail:LookupEvents

Dashboards past the free three are billed monthly

CloudWatch pricing includes 3 custom dashboards that reference up to 50 metrics each per month in the free tier, and automatic dashboards are free. Every custom dashboard beyond that is charged per dashboard per month. Teams build a dashboard for a launch, an incident or a quarterly review, and they accumulate.

A dashboard nobody opens is paying for a view no one takes.

Finding out when a dashboard was last opened

CloudWatch does not store a “last viewed” field. list-dashboards returns LastModified, which changes only when someone edits the dashboard. Views show up as GetDashboard API calls, which CloudTrail records along with calls made from the console. CloudTrail’s event history keeps 90 days of management events per Region:

Terminal window
aws cloudwatch list-dashboards \
--query 'DashboardEntries[].[DashboardName,LastModified]' --output table
aws cloudtrail lookup-events \
--lookup-attributes AttributeKey=EventName,AttributeValue=GetDashboard \
--query 'Events[].[EventTime,Username]' --output table

Compare the dashboard names in the event records with the full list.

The 45-day rule and the view record

ZopNight reads the same kind of view events, keeps the latest one per dashboard, and measures the days since. A dashboard whose last view is at least 45 days old, and whose monthly cost is above zero, gets a finding. The saving is the whole dashboard fee.

Dashboards that are not flagged

Most dashboards cost nothing because they fall inside the free allowance, and a $0 dashboard is never flagged. A dashboard with no captured view at all is also left alone: ZopNight looks back over roughly the last 90 days of events, so a dashboard untouched for longer than that has no view to measure from, and without permission to read the events there is no signal either. In practice this means findings cover dashboards last opened between about 45 and 90 days ago; long-abandoned ones need the manual check above or a trail with longer retention.

One dashboard fee per finding

Terminal window
saving = monthly charge for the dashboard
cost after fix = 0

Retiring stale dashboards

  1. Check the view history above and ask the dashboard’s owner whether anyone still relies on it.
  2. Export the body with aws cloudwatch get-dashboard --dashboard-name if you may want it back.
  3. Delete it with aws cloudwatch delete-dashboards --dashboard-names.
  4. Consolidate related dashboards so the account stays near the free allowance.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·