Timestream for LiveAnalytics databases in accounts that metered almost no data for 30 days
What does ZopNight detect here?
ZopNight flags an Amazon Timestream for LiveAnalytics database when the account's `CumulativeBytesMetered` metric peaks at or below 1 MiB across 30 distinct days, meaning almost no ingestion or queries. Stored data keeps billing, but ZopNight raises a finding only when billing data attributes a cost to the database, so most accounts see none today.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-194 |
| Category | idle |
| Severity | medium |
| Metric | CumulativeBytesMetered |
| Threshold | 1 MiB peak metered bytes |
| Evaluation window | 30d |
| Source | ZopNight |
| Permissions used | resource-explorer-2:Search · cloudwatch:GetMetricStatistics |
Where it applies
Stored time series keep billing when nobody reads them
Timestream pricing splits the LiveAnalytics bill into writes, queries, memory store and magnetic store. Memory store is billed per GB-hour for each table and magnetic store per GB-month, with magnetic storage billed for a minimum of 100 GB per account in a Region. Stop writing and querying, and the two storage lines carry on.
There is a second reason to look at these databases now. AWS closed new customer access to Timestream for LiveAnalytics effective 6/20/25 and points to Timestream for InfluxDB for similar capabilities. A quiet LiveAnalytics database is a good moment to decide between deleting and migrating.
Checking metered bytes and inventory
aws timestream-write list-databases \ --query 'Databases[].[DatabaseName,TableCount]' --output table
aws cloudwatch get-metric-statistics \ --namespace AWS/Timestream --metric-name CumulativeBytesMetered \ --dimensions Name=Operation,Value=Query \ --start-time 2026-08-26T00:00:00Z --end-time 2026-09-25T00:00:00Z \ --period 86400 --statistics SumRepeat the metric call with Operation=WriteRecords to see ingestion. The
Timestream metrics page
notes that CumulativeBytesMetered has only the Operation dimension and only the Sum
statistic.
What the 30-day, 1 MiB gate measures
Because the metric has no database or table dimension, the signal is account-wide: it describes all LiveAnalytics activity in the Region, not one database. ZopNight fires only when that series covers at least 30 distinct days and its peak is at or below 1 MiB. Distinct days are counted rather than filled slots, because an idle account reports gappy data by nature. Exactly 1 MiB still counts as idle; anything above it does not.
Cases that produce no finding
A series with fewer than 30 days of coverage is not enough evidence for a delete, so the database waits. Any peak above 1 MiB ends it. A database with no price in ZopNight’s cost data, or a price of zero, is skipped rather than shown with an invented figure. Because the evidence is account-level, one busy database keeps every database in that account and Region off the list.
Pricing the standing storage
saving = database standing monthly cost (memory store + magnetic store)cost after fix = 0ZopNight does not yet price Timestream storage itself: its own cost calculation returns no figure for these databases. A finding appears only when billing data attributes a cost to the database, so in most accounts this rule raises nothing today.
Retiring or migrating the database
- Confirm no application, Grafana dashboard or scheduled query reads it.
- Export the data you must keep, for archive or for loading into Timestream for InfluxDB.
- Delete each table with
aws timestream-write delete-table --database-nameand--table-name. - Delete the empty database with
aws timestream-write delete-database --database-name.