Skip to main content
rightsizing · aws

CloudWatch metric streams that may be streaming namespaces nobody uses

resource types
1
rule IDs covered
1
severity
low

What does ZopNight detect here?

CloudWatch metric streams bill $0.003 per 1,000 metric updates in us-east-1, plus Amazon Data Firehose delivery. ZopNight lists running streams but raises no dollar finding, because the `MetricUpdate` metric is split by `MetricStreamName` only, with no namespace dimension, so it cannot show how much of a stream's volume comes from each namespace you might exclude.

Signal and threshold

How ZopNight evaluates CloudWatch metric streams that may be streaming namespaces nobody uses.
Field Value
Rule IDsRC-177
Categoryrightsizing
Severitylow
Metricnone — pure configuration read
Thresholdactive, priced metric stream
SourceZopNight
Permissions usedcloudwatch:ListMetricStreams · cloudwatch:GetMetricStream · cloudwatch:GetMetricStatistics

Streams bill per metric update, not per stream

Metric streams push CloudWatch metrics continuously to Amazon Data Firehose, for delivery to S3 or to a partner such as Datadog, Dynatrace, New Relic or Splunk. With no filters, a stream sends every metric in the account and Region, including new ones as they appear.

CloudWatch pricing charges per metric update. One update carries the four default statistics (minimum, maximum, sample count and sum), and each extra five statistics you request for a metric count as another update. The AWS price list for US East (N. Virginia) sets the rate at $0.003 per 1,000 metric updates, and Firehose charges for delivery on top. A stream left on “all metrics” when the tool on the other end only charts EC2 and RDS pays for every other namespace too.

Checking what each stream sends

Terminal window
aws cloudwatch list-metric-streams \
--query 'Entries[].[Name,State,OutputFormat,FirehoseArn]' --output table
aws cloudwatch get-metric-stream --name my-stream \
--query '[IncludeFilters,ExcludeFilters,StatisticsConfigurations]'

Empty include and exclude lists mean the stream sends everything. The stream’s own volume is in the MetricUpdate metric in the AWS/CloudWatch/MetricStreams namespace, which is emitted only while the stream is running.

What would have to be measured

The only lever is removing namespaces the destination does not use, so a real saving is the stream’s monthly cost multiplied by the share of its updates those namespaces produce. ZopNight can price a running stream, and the stream’s total update count can be read. The share cannot. MetricUpdate is published per stream and as an account total, with a MetricStreamName dimension and no namespace split, and the stream configuration lists the namespaces without any counts.

Why this stays advisory permanently

Splitting the total by a guessed ratio would invent the number the recommendation depends on, so the rule does not produce a finding for any stream. This is not waiting on a missing data feed: AWS does not publish the breakdown. Use the steps below to size the saving yourself.

Estimating the saving by hand

Terminal window
saving = stream monthly cost x (updates from excludable namespaces / total updates)

To estimate the fraction, count the metrics per namespace with aws cloudwatch list-metrics --namespace AWS/EC2 and similar, multiply by the updates each sends per month, and compare with the MetricUpdate total.

Cutting a stream down to what is used

  1. Ask the owners of the destination which namespaces their dashboards and alerts read.
  2. Add filters with aws cloudwatch put-metric-stream, passing the same name, Firehose ARN, role ARN and output format. A stream can have up to 1,000 filters, but only include filters or only exclude filters, not both.
  3. Drop additional statistics you do not chart, since each extra five count as another update.
  4. Delete the stream with aws cloudwatch delete-metric-stream if nothing downstream reads it.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·