Load balancers with no registered targets and zero traffic for 30 days
What does ZopNight detect here?
ZopNight flags Elastic Load Balancing load balancers with no registered targets whose traffic metrics are all zero for 30 days, including `ConsumedLCUs`, which AWS always reports. An Application Load Balancer is charged for each hour or partial hour it runs, so deleting an idle one saves its full monthly cost.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-012 |
| Category | idle |
| Severity | medium |
| Metric | ConsumedLCUs |
| Threshold | zero traffic, no registered targets |
| Evaluation window | 30d |
| Source | ZopNight |
| Permissions used | elasticloadbalancing:DescribeLoadBalancers · elasticloadbalancing:DescribeTargetGroups · elasticloadbalancing:DescribeTargetHealth · cloudwatch:GetMetricStatistics |
A load balancer charges by the hour before it carries a byte
Elastic Load Balancing pricing charges an Application Load Balancer for each hour or partial hour it is running, with partial hours billed as full hours, plus Load Balancer Capacity Units (LCUs) for the work it does. Take away the traffic and the LCU charge falls to almost nothing, but the hourly charge stays. Load balancers outlive the services they fronted surprisingly often, especially ones created by infrastructure templates or Kubernetes controllers.
Why the obvious metric is not enough
The ALB metrics reference
notes that RequestCount is only reported when targets are registered. A load balancer with no
backends therefore shows no request datapoints at all rather than zeros. ConsumedLCUs, by
contrast, is always reported, so it is the dependable signal for an idle load balancer.
aws elbv2 describe-load-balancers \ --query 'LoadBalancers[].[LoadBalancerName,Type,State.Code,LoadBalancerArn]'
aws elbv2 describe-target-groups --load-balancer-arn <lb-arn> \ --query 'TargetGroups[].TargetGroupArn'aws elbv2 describe-target-health --target-group-arn <tg-arn>
aws cloudwatch get-metric-statistics --namespace AWS/ApplicationELB --metric-name ConsumedLCUs \ --dimensions Name=LoadBalancer,Value=app/orders-alb/50dc6c495c0c9188 \ --start-time 2026-08-26T00:00:00Z --end-time 2026-09-25T00:00:00Z \ --period 86400 --statistics SumThe traffic test depends on the load balancer type
For Application and Classic Load Balancers, ZopNight reads RequestCount,
ActiveConnectionCount, ActiveFlowCount, ProcessedBytes and ConsumedLCUs. For Network Load
Balancers, which publish no request count, it reads ActiveFlowCount, ProcessedBytes,
ActiveConnectionCount and ConsumedLCUs. Every metric that is present must be zero on average
and maximum over 30 days. The finding names exactly the metrics that were measured at zero.
Load balancers that are skipped
Any load balancer with registered targets is skipped, since it is wired into a serving path even if traffic is low. If none of the traffic metrics could be read, nothing is raised. A load balancer that belongs to an abandoned EKS cluster is counted once, under EKS Abandoned Node Group, instead of here. No price means no finding.
The saving is the full monthly cost
saving = monthly cost of the load balancer (hours plus any LCUs)cost after deletion = 0Removing the load balancer
- Check Route 53 and other DNS for records pointing at its DNS name.
- Check deletion protection:
aws elbv2 describe-load-balancer-attributes --load-balancer-arn <lb-arn>, and turn it off withmodify-load-balancer-attributesif needed. - Delete it:
aws elbv2 delete-load-balancer --load-balancer-arn <lb-arn> - Delete its now-unused target groups:
aws elbv2 delete-target-group --target-group-arn <tg-arn>