Skip to main content
idle · aws

Neptune clusters with no Gremlin, SPARQL or openCypher requests and under 5% CPU

resource types
1
rule IDs covered
1
severity
high

What does ZopNight detect here?

ZopNight flags Amazon Neptune clusters whose `CPUUtilization` stays below 5% on average and peak across 30 covered days while `GremlinRequestsPerSec`, `SparqlRequestsPerSec` and `OpenCypherRequestsPerSec` stay below 0.10 or report nothing. Neptune publishes metrics only when they are non-zero, so a silent request metric counts as idle. The saving is one instance-class hourly rate times hours run.

Signal and threshold

How ZopNight evaluates Neptune clusters with no Gremlin, SPARQL or openCypher requests and under 5% CPU.
Field Value
Rule IDsRC-192
Categoryidle
Severityhigh
MetricGremlinRequestsPerSec
Thresholdrequests < 0.10/s, CPU < 5%
Evaluation window30d
SourceZopNight
Permissions usedrds:DescribeDBClusters · rds:DescribeDBInstances · cloudwatch:GetMetricStatistics

Neptune instances bill by the hour whether or not a query arrives

A Neptune cluster pays for each DB instance by the hour, plus storage and backups. The stop and start guide says a stopped cluster is charged only for storage, manual snapshots and automated backups, but Neptune starts the cluster again automatically after seven days. For a graph nobody queries, the instance hours are pure waste and stopping is only a short reprieve.

Reading Neptune’s request metrics

The Neptune metrics guide opens with an important note: Neptune sends metrics to CloudWatch only when they have a non-zero value. An idle cluster therefore shows no request datapoints at all, which is easy to misread as a monitoring gap. Neptune has a request metric for each query language it speaks: GremlinRequestsPerSec, SparqlRequestsPerSec and OpenCypherRequestsPerSec.

Terminal window
aws neptune describe-db-clusters --filters Name=engine,Values=neptune \
--query 'DBClusters[].[DBClusterIdentifier,Status]'
aws cloudwatch get-metric-statistics --namespace AWS/Neptune --metric-name GremlinRequestsPerSec \
--dimensions Name=DBClusterIdentifier,Value=graph-prod \
--start-time 2026-08-26T00:00:00Z --end-time 2026-09-25T00:00:00Z \
--period 86400 --statistics Maximum

CPU anchors the evidence

Because quiet request metrics disappear, ZopNight uses CPUUtilization, which a running instance reports continuously, to prove it has a full month of observation:

  • CPUUtilization is present, covers at least 30 days, and stays below 5% on both average and maximum.
  • Each of the three request metrics is either absent, or present with every reading below 0.10 requests per second.
  • ZopNight has a real monthly price for the cluster: the instance class hourly rate times the hours it ran. That figure covers one instance’s compute and leaves out storage.

Clusters that are not flagged

Any request metric with a reading above 0.10 per second, even briefly, clears the cluster. So does CPU at or above 5% on average or at peak, which suggests replication, maintenance or a batch process doing work. Missing or short CPU data means ZopNight cannot prove a month of quiet, so it says nothing. Without a price, there is no finding.

Pricing a cluster nobody queries

Terminal window
saving = instance class hourly rate x hours running (up to 730 a month)
cost after deletion = 0

This is advisory. ZopNight does not stop the cluster automatically, since a stop would reverse itself within a week.

Retiring the graph

  1. Confirm no application or notebook connects to the cluster or reader endpoints.
  2. Delete the instances: aws neptune delete-db-instance --db-instance-identifier graph-prod-1
  3. Delete the cluster with a final snapshot: aws neptune delete-db-cluster --db-cluster-identifier graph-prod --final-db-snapshot-identifier graph-prod-final
  4. For graphs used only occasionally, consider Neptune Serverless when you next need one.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·