Skip to main content
idle · aws

Lambda functions averaging fewer than 1 invocation a day over 30 days

resource types
1
rule IDs covered
1
severity
medium

What does ZopNight detect here?

ZopNight flags AWS Lambda functions whose total `Invocations`, summed over the last 30 days, works out to fewer than 1 per day, when the function still has a positive monthly cost in ZopNight. That cost comes from measured requests and duration, or from billed cost when billing data is connected.

Signal and threshold

How ZopNight evaluates Lambda functions averaging fewer than 1 invocation a day over 30 days.
Field Value
Rule IDsRC-010
Categoryidle
Severitymedium
MetricInvocations
Thresholdfewer than 1 invocation per day
Evaluation window30d
SourceZopNight
Permissions usedlambda:ListFunctions · lambda:GetFunction · lambda:ListEventSourceMappings · cloudwatch:GetMetricStatistics

Most idle functions are free; the ones that are not have something provisioned

Lambda pricing charges functions for the requests they serve and the duration their code runs, in GB-seconds. A function that is never called has no request or duration cost at all. Provisioned Concurrency changes that: you pay for the amount of concurrency you configure and for the period it is configured, whether or not it is invoked. SnapStart snapshots are another standing item, charged for as long as the function version is active.

That is why this rule only reports functions with a real monthly cost. ZopNight prices a function from its measured requests and duration, or from its billed cost when billing data is connected; it does not read provisioned concurrency settings itself. An idle function with nothing provisioned is clutter, not spend.

Counting invocations correctly

AWS’s metric guide says invocation metrics should be read with the Sum statistic. The average of Invocations is not useful for counting calls.

Terminal window
aws cloudwatch get-metric-statistics --namespace AWS/Lambda --metric-name Invocations \
--dimensions Name=FunctionName,Value=legacy-export \
--start-time 2026-08-26T00:00:00Z --end-time 2026-09-25T00:00:00Z \
--period 86400 --statistics Sum
aws lambda list-provisioned-concurrency-configs --function-name legacy-export

How the daily rate is computed

ZopNight sums the hourly invocation totals across the last 30 days and divides by the number of days covered. The function is idle when that rate is below 1 invocation per day, so a function called 20 times in a month still qualifies. It must also have a positive monthly cost in ZopNight.

When no finding appears

A function with no invocation data at all is skipped: absent data is not treated as proof of no use. Functions called more than about once a day are left alone. So are idle functions with no cost, which is most of them. Functions that are used but tuned badly belong to Lambda Over-Provisioned Memory.

The saving is the whole function cost

Terminal window
saving = monthly cost of the function (measured request and duration cost, or its billed cost)
cost after deletion = 0

Removing an idle function

  1. List triggers: aws lambda list-event-source-mappings --function-name legacy-export, and check EventBridge rules, API Gateway routes and S3 notifications.
  2. Remove provisioned concurrency first if you want the charge to stop while you confirm: aws lambda delete-provisioned-concurrency-config --function-name legacy-export --qualifier live
  3. Save the code package from the Code.Location URL returned by aws lambda get-function --function-name legacy-export.
  4. Delete: aws lambda delete-function --function-name legacy-export

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·