Skip to main content
rightsizing · aws

Standard-class CloudWatch log groups with no subscription or metric filters that could ingest at the Infrequent Access rate

resource types
1
rule IDs covered
1
severity
low

What does ZopNight detect here?

ZopNight flags Standard-class CloudWatch log groups holding at least 1 GB that have zero subscription filters and zero metric filters. Infrequent Access ingests at $0.25 per GB instead of $0.50 in us-east-1, so the saving is the group's measured `IncomingBytes` for a 30-day month times that $0.25 difference.

Signal and threshold

How ZopNight evaluates Standard-class CloudWatch log groups with no subscription or metric filters that could ingest at the Infrequent Access rate.
Field Value
Rule IDsRC-1518
Categoryrightsizing
Severitylow
MetricIncomingBytes
Thresholdlog class STANDARD, 0 subscription filters, 0 metric filters, >= 1 GB stored
Evaluation window30d
SourceZopNight
Permissions usedlogs:DescribeLogGroups · logs:DescribeSubscriptionFilters · logs:DescribeMetricFilters · cloudwatch:GetMetricStatistics

Half-price ingestion, fewer features

CloudWatch Logs offers two main log classes, and they differ in ingestion price only: storage and Logs Insights charges are the same. The AWS price list for US East (N. Virginia) charges $0.50 per GB of custom log data ingested into Standard and $0.25 per GB into Infrequent Access. For a group taking in 200 GB a month, that is $50 a month.

The trade is features. Infrequent Access has no subscription filters, no metric filters, no Live Tail, no anomaly detection, and no GetLogEvents or FilterLogEvents; you read the data with Logs Insights instead. And the class is fixed at creation. AWS states that after a log group is created, its log class cannot be changed.

Finding Standard groups nothing streams from

Terminal window
aws logs describe-log-groups --log-group-class STANDARD \
--query 'logGroups[].[logGroupName,storedBytes]' --output table
aws logs describe-subscription-filters --log-group-name /app/api \
--query 'length(subscriptionFilters)'
aws logs describe-metric-filters --log-group-name /app/api \
--query 'length(metricFilters)'

For each group where both counts are zero, read IncomingBytes from the AWS/Logs namespace with the LogGroupName dimension and Sum statistic to see its monthly ingestion.

  1. The class AWS reports for the group is STANDARD.
  2. ZopNight has counted the group’s subscription filters and metric filters and both are zero. If either count could not be read, nothing is recommended, since a switch would silently break whatever those filters feed.
  3. The group holds at least 1 GB, going by its stored size or the StoredBytes metric.
  4. IncomingBytes over the last 30 days is present and above zero.

Groups that are passed over

Groups already on Infrequent Access, groups with any filter, small groups and groups with no measured ingestion are all skipped. The rule looks only at filters it can count; it cannot see people who open the group in the console or tools that call GetLogEvents, so check for those yourself. Log groups with no retention at all are covered separately by CloudWatch Log Group No Retention.

Ingestion volume times the rate gap

Terminal window
monthly ingest GB = IncomingBytes over 30 days, in GB
saving = monthly ingest GB x ($0.50 - $0.25)
current cost = larger of the group's monthly cost and monthly ingest GB x $0.50
cost after change = current cost - saving, never below monthly ingest GB x $0.25

Storage is priced the same in both classes, so it adds nothing to the saving. Results under $5 a month are not shown.

Moving ingestion to a new Infrequent Access group

  1. Create the new group: aws logs create-log-group --log-group-name /app/api-ia --log-group-class INFREQUENT_ACCESS
  2. Give it the same retention policy as the old group.
  3. Point the log source (agent config, Lambda logging config, service setting) at the new group.
  4. Keep the old group until its retention runs out, then delete it.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·