Skip to main content
rightsizing · aws

High Cross-Region Data Transfer

resource types
1
rule IDs covered
1
severity
medium

What does ZopNight detect here?

High cross-region transfer fires when an account moves at least 100 GB between AWS regions with real billed egress on the -AWS-Out-Bytes usage types. ZopNight takes actual Cost Explorer dollars as the cost basis and marks 50% as recoverable through colocation, since DR replication and multi-region HA traffic cannot be eliminated.

Signal and threshold

How ZopNight evaluates High Cross-Region Data Transfer.
Field Value
Rule IDsRC-178
Categoryrightsizing
Severitymedium
Metricnone — pure configuration read
Sourcedata_transfer_cross_region.go

The Cost Explorer egress signal

  • Metadata: cross_region_transfer_gb (≥100 GB; new Cost-Explorer DataTransferProvider → account-level data-transfer-account row)
  • Metadata: cross_region_transfer_cost_usd (REAL billed inter-region egress, CE UnblendedCost on -AWS-Out-Bytes usage types; PRODUCER WIRED: DataTransferProvider requests UnblendedCost on the same ce:GetCostAndUsage call and sums it over the same groups)

Why only half the egress is recoverable

concrete-or-abstain. CurrentCostUSD = cross_region_transfer_cost_usd (the full billed inter-region egress line item, real CE UnblendedCost actuals, not a 730×rate or fraction-of-compute); savings = cross_region_transfer_cost_usd × 0.50 (crossRegionReductionFactor, the conservatively-recoverable share: a large part of cross-region traffic is architecturally required (DR/replication, multi-region HA, backups) and cannot be colocated away, mirroring RC-065’s 0.30 honesty for the cross-AZ line item); OptimizedCostUSD = the residual. FIRES CONCRETELY: the discoverer producer was wired (it adds UnblendedCost to the same GetCostAndUsage Metrics and sums it over the same -AWS-Out-Bytes groups, stamping cross_region_transfer_cost_usd alongside cross_region_transfer_gb). No new SDK call and no permissions change; same ce:GetCostAndUsage. The rule still abstains when CE reports no billed inter-region egress (cost key omitted, ≤0) rather than ship a $0/advisory cost rec.

Colocating the chattiest region pairs

  1. In Cost Explorer, group by Usage Type and filter to inter-region ‘-AWS-Out-Bytes’ to find the heaviest region pairs, priced at AWS’s published inter-region transfer rates
  2. Colocate services that chatter across regions into the same region
  3. Use VPC endpoints / PrivateLink to reduce data transfer and NAT costs
  4. Compress or batch data before cross-region transfer

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

417 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

417 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·