Skip to main content
compliance · aws

Running production EC2 instances limited to 5-minute basic monitoring

resource types
1
rule IDs covered
1
severity
low

What does ZopNight detect here?

ZopNight flags a running EC2 instance whose `monitoring-state` is `disabled`, meaning CloudWatch receives metrics only every 5 minutes. Instances that look like dev or test are skipped unless tagged as production, because detailed monitoring is a paid add-on at $0.30 per metric per month. The finding carries no saving; enabling it adds a small cost.

Signal and threshold

How ZopNight evaluates Running production EC2 instances limited to 5-minute basic monitoring.
Field Value
Rule IDsRC-151
Categorycompliance
Severitylow
Metricnone — pure configuration read
Thresholdmonitoring-state = disabled
SourceZopNight
Permissions usedec2:DescribeInstances

Five-minute metrics hide short spikes

The EC2 detailed monitoring guide sets out the difference. Basic monitoring, the default, publishes status checks every minute and all other metrics in 5-minute periods at no charge. Detailed monitoring publishes metrics in 1-minute periods and is charged per metric. On a production instance, a CPU spike that lasts two minutes can vanish inside a 5-minute average, and alarms or scaling policies keyed to those metrics react up to five minutes late.

Finding running instances on basic monitoring

Terminal window
aws ec2 describe-instances \
--filters Name=instance-state-name,Values=running Name=monitoring-state,Values=disabled \
--query 'Reservations[].Instances[].[InstanceId,InstanceType,Tags[?Key==`Name`]|[0].Value]' \
--output table

The gates before a finding

Three things must be true. The instance must be running. ZopNight must have read its monitoring setting from AWS and seen that detailed monitoring is off; if the setting was not reported, nothing fires. And the instance must not look like a development or test machine.

How non-production instances are excluded

Because this rule asks you to spend money, ZopNight skips instances whose name or environment tag (such as env, environment, stage or tier) marks them as dev or test. An explicit production environment tag overrides that, so a box named test-runner but tagged environment=prod is still evaluated.

A cost increase, not a saving

This finding never adds to savings totals. Enabling detailed monitoring raises spend: CloudWatch pricing charges detailed monitoring metrics as custom metrics, $0.30 per metric per month for the first 10,000, prorated by the hour. The pricing page’s own example assumes 7 metrics per instance, which works out to $2.10 a month; the real count depends on instance type.

Terminal window
monthly cost of enabling = metrics sent by the instance x $0.30

Turning on detailed monitoring

  1. Select the instance in the EC2 console.
  2. Choose Actions, Monitor and troubleshoot, Manage detailed monitoring, and enable it. From the CLI: aws ec2 monitor-instances --instance-ids i-0123456789abcdef0.
  3. Update alarms and scaling policies to use 60-second periods so they benefit from the finer data.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·