Skip to main content
idle · aws

Load balancers with no registered targets and zero traffic for 30 days

rule IDs covered
1
severity
medium

What does ZopNight detect here?

ZopNight flags Elastic Load Balancing load balancers with no registered targets whose traffic metrics are all zero for 30 days, including `ConsumedLCUs`, which AWS always reports. An Application Load Balancer is charged for each hour or partial hour it runs, so deleting an idle one saves its full monthly cost.

Signal and threshold

How ZopNight evaluates Load balancers with no registered targets and zero traffic for 30 days.
Field Value
Rule IDsRC-012
Categoryidle
Severitymedium
MetricConsumedLCUs
Thresholdzero traffic, no registered targets
Evaluation window30d
SourceZopNight
Permissions usedelasticloadbalancing:DescribeLoadBalancers · elasticloadbalancing:DescribeTargetGroups · elasticloadbalancing:DescribeTargetHealth · cloudwatch:GetMetricStatistics

A load balancer charges by the hour before it carries a byte

Elastic Load Balancing pricing charges an Application Load Balancer for each hour or partial hour it is running, with partial hours billed as full hours, plus Load Balancer Capacity Units (LCUs) for the work it does. Take away the traffic and the LCU charge falls to almost nothing, but the hourly charge stays. Load balancers outlive the services they fronted surprisingly often, especially ones created by infrastructure templates or Kubernetes controllers.

Why the obvious metric is not enough

The ALB metrics reference notes that RequestCount is only reported when targets are registered. A load balancer with no backends therefore shows no request datapoints at all rather than zeros. ConsumedLCUs, by contrast, is always reported, so it is the dependable signal for an idle load balancer.

Terminal window
aws elbv2 describe-load-balancers \
--query 'LoadBalancers[].[LoadBalancerName,Type,State.Code,LoadBalancerArn]'
aws elbv2 describe-target-groups --load-balancer-arn <lb-arn> \
--query 'TargetGroups[].TargetGroupArn'
aws elbv2 describe-target-health --target-group-arn <tg-arn>
aws cloudwatch get-metric-statistics --namespace AWS/ApplicationELB --metric-name ConsumedLCUs \
--dimensions Name=LoadBalancer,Value=app/orders-alb/50dc6c495c0c9188 \
--start-time 2026-08-26T00:00:00Z --end-time 2026-09-25T00:00:00Z \
--period 86400 --statistics Sum

The traffic test depends on the load balancer type

For Application and Classic Load Balancers, ZopNight reads RequestCount, ActiveConnectionCount, ActiveFlowCount, ProcessedBytes and ConsumedLCUs. For Network Load Balancers, which publish no request count, it reads ActiveFlowCount, ProcessedBytes, ActiveConnectionCount and ConsumedLCUs. Every metric that is present must be zero on average and maximum over 30 days. The finding names exactly the metrics that were measured at zero.

Load balancers that are skipped

Any load balancer with registered targets is skipped, since it is wired into a serving path even if traffic is low. If none of the traffic metrics could be read, nothing is raised. A load balancer that belongs to an abandoned EKS cluster is counted once, under EKS Abandoned Node Group, instead of here. No price means no finding.

The saving is the full monthly cost

Terminal window
saving = monthly cost of the load balancer (hours plus any LCUs)
cost after deletion = 0

Removing the load balancer

  1. Check Route 53 and other DNS for records pointing at its DNS name.
  2. Check deletion protection: aws elbv2 describe-load-balancer-attributes --load-balancer-arn <lb-arn>, and turn it off with modify-load-balancer-attributes if needed.
  3. Delete it: aws elbv2 delete-load-balancer --load-balancer-arn <lb-arn>
  4. Delete its now-unused target groups: aws elbv2 delete-target-group --target-group-arn <tg-arn>

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·