Skip to main content
idle · aws

Timestream for LiveAnalytics databases in accounts that metered almost no data for 30 days

resource types
1
rule IDs covered
1
severity
medium

What does ZopNight detect here?

ZopNight flags an Amazon Timestream for LiveAnalytics database when the account's `CumulativeBytesMetered` metric peaks at or below 1 MiB across 30 distinct days, meaning almost no ingestion or queries. Stored data keeps billing, but ZopNight raises a finding only when billing data attributes a cost to the database, so most accounts see none today.

Signal and threshold

How ZopNight evaluates Timestream for LiveAnalytics databases in accounts that metered almost no data for 30 days.
Field Value
Rule IDsRC-194
Categoryidle
Severitymedium
MetricCumulativeBytesMetered
Threshold1 MiB peak metered bytes
Evaluation window30d
SourceZopNight
Permissions usedresource-explorer-2:Search · cloudwatch:GetMetricStatistics

Stored time series keep billing when nobody reads them

Timestream pricing splits the LiveAnalytics bill into writes, queries, memory store and magnetic store. Memory store is billed per GB-hour for each table and magnetic store per GB-month, with magnetic storage billed for a minimum of 100 GB per account in a Region. Stop writing and querying, and the two storage lines carry on.

There is a second reason to look at these databases now. AWS closed new customer access to Timestream for LiveAnalytics effective 6/20/25 and points to Timestream for InfluxDB for similar capabilities. A quiet LiveAnalytics database is a good moment to decide between deleting and migrating.

Checking metered bytes and inventory

Terminal window
aws timestream-write list-databases \
--query 'Databases[].[DatabaseName,TableCount]' --output table
aws cloudwatch get-metric-statistics \
--namespace AWS/Timestream --metric-name CumulativeBytesMetered \
--dimensions Name=Operation,Value=Query \
--start-time 2026-08-26T00:00:00Z --end-time 2026-09-25T00:00:00Z \
--period 86400 --statistics Sum

Repeat the metric call with Operation=WriteRecords to see ingestion. The Timestream metrics page notes that CumulativeBytesMetered has only the Operation dimension and only the Sum statistic.

What the 30-day, 1 MiB gate measures

Because the metric has no database or table dimension, the signal is account-wide: it describes all LiveAnalytics activity in the Region, not one database. ZopNight fires only when that series covers at least 30 distinct days and its peak is at or below 1 MiB. Distinct days are counted rather than filled slots, because an idle account reports gappy data by nature. Exactly 1 MiB still counts as idle; anything above it does not.

Cases that produce no finding

A series with fewer than 30 days of coverage is not enough evidence for a delete, so the database waits. Any peak above 1 MiB ends it. A database with no price in ZopNight’s cost data, or a price of zero, is skipped rather than shown with an invented figure. Because the evidence is account-level, one busy database keeps every database in that account and Region off the list.

Pricing the standing storage

Terminal window
saving = database standing monthly cost (memory store + magnetic store)
cost after fix = 0

ZopNight does not yet price Timestream storage itself: its own cost calculation returns no figure for these databases. A finding appears only when billing data attributes a cost to the database, so in most accounts this rule raises nothing today.

Retiring or migrating the database

  1. Confirm no application, Grafana dashboard or scheduled query reads it.
  2. Export the data you must keep, for archive or for loading into Timestream for InfluxDB.
  3. Delete each table with aws timestream-write delete-table --database-name and --table-name.
  4. Delete the empty database with aws timestream-write delete-database --database-name.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·