Standard-class CloudWatch log groups with no subscription or metric filters that could ingest at the Infrequent Access rate
What does ZopNight detect here?
ZopNight flags Standard-class CloudWatch log groups holding at least 1 GB that have zero subscription filters and zero metric filters. Infrequent Access ingests at $0.25 per GB instead of $0.50 in us-east-1, so the saving is the group's measured `IncomingBytes` for a 30-day month times that $0.25 difference.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1518 |
| Category | rightsizing |
| Severity | low |
| Metric | IncomingBytes |
| Threshold | log class STANDARD, 0 subscription filters, 0 metric filters, >= 1 GB stored |
| Evaluation window | 30d |
| Source | ZopNight |
| Permissions used | logs:DescribeLogGroups · logs:DescribeSubscriptionFilters · logs:DescribeMetricFilters · cloudwatch:GetMetricStatistics |
Where it applies
Half-price ingestion, fewer features
CloudWatch Logs offers two main log classes, and they differ in ingestion price only: storage and Logs Insights charges are the same. The AWS price list for US East (N. Virginia) charges $0.50 per GB of custom log data ingested into Standard and $0.25 per GB into Infrequent Access. For a group taking in 200 GB a month, that is $50 a month.
The trade is features. Infrequent Access has no subscription filters, no metric filters, no Live
Tail, no anomaly detection, and no GetLogEvents or FilterLogEvents; you read the data with Logs
Insights instead. And the class is fixed at creation. AWS states that after a log group is created,
its log class cannot be changed.
Finding Standard groups nothing streams from
aws logs describe-log-groups --log-group-class STANDARD \ --query 'logGroups[].[logGroupName,storedBytes]' --output table
aws logs describe-subscription-filters --log-group-name /app/api \ --query 'length(subscriptionFilters)'
aws logs describe-metric-filters --log-group-name /app/api \ --query 'length(metricFilters)'For each group where both counts are zero, read IncomingBytes from the AWS/Logs namespace with
the LogGroupName dimension and Sum statistic to see its monthly ingestion.
Checks before a log group is recommended
- The class AWS reports for the group is
STANDARD. - ZopNight has counted the group’s subscription filters and metric filters and both are zero. If either count could not be read, nothing is recommended, since a switch would silently break whatever those filters feed.
- The group holds at least 1 GB, going by its stored size or the
StoredBytesmetric. IncomingBytesover the last 30 days is present and above zero.
Groups that are passed over
Groups already on Infrequent Access, groups with any filter, small groups and groups with no
measured ingestion are all skipped. The rule looks only at filters it can count; it cannot see
people who open the group in the console or tools that call GetLogEvents, so check for those
yourself. Log groups with no retention at all are covered separately by
CloudWatch Log Group No Retention.
Ingestion volume times the rate gap
monthly ingest GB = IncomingBytes over 30 days, in GBsaving = monthly ingest GB x ($0.50 - $0.25)current cost = larger of the group's monthly cost and monthly ingest GB x $0.50cost after change = current cost - saving, never below monthly ingest GB x $0.25Storage is priced the same in both classes, so it adds nothing to the saving. Results under $5 a month are not shown.
Moving ingestion to a new Infrequent Access group
- Create the new group:
aws logs create-log-group --log-group-name /app/api-ia --log-group-class INFREQUENT_ACCESS - Give it the same retention policy as the old group.
- Point the log source (agent config, Lambda logging config, service setting) at the new group.
- Keep the old group until its retention runs out, then delete it.