Skip to main content
rightsizing · aws

VPC flow logs delivered to CloudWatch Logs at $0.50 per GB when S3 delivery costs $0.25

resource types
1
rule IDs covered
1
severity
low

What does ZopNight detect here?

ZopNight flags VPCs whose flow logs publish to CloudWatch Logs and measures the log group's `IncomingBytes` over 30 days. Vended log delivery to CloudWatch Logs costs $0.50 per GB for the first 10 TB in us-east-1, against $0.25 per GB to S3, so ZopNight prices the switch at that gap minus S3 storage.

Signal and threshold

How ZopNight evaluates VPC flow logs delivered to CloudWatch Logs at $0.50 per GB when S3 delivery costs $0.25.
Field Value
Rule IDsRC-055
Categoryrightsizing
Severitylow
MetricIncomingBytes (AWS/Logs)
Threshold>= 1 GB per month to a CloudWatch Logs destination
Evaluation window30d
SourceZopNight
Permissions usedec2:DescribeFlowLogs · cloudwatch:GetMetricStatistics

Flow logs are billed as vended logs at every destination

VPC Flow Logs are not free to deliver anywhere. The flow logs pricing note says that data ingestion and archival charges for vended logs apply when you publish them, and the S3 destination page repeats that for S3. The difference is the rate. AWS’s price list for US East (N. Virginia) charges $0.50 per GB for the first 10 TB of vended logs ingested into CloudWatch Logs each month and $0.25 per GB for the first 10 TB delivered to S3, with lower tiers above that. The CloudWatch pricing page adds $0.03 per GB for archiving the data in CloudWatch Logs.

A busy VPC can produce hundreds of gigabytes of flow records a month, so the destination choice shows up on the bill.

Measuring what each flow log sends to CloudWatch Logs

Terminal window
aws ec2 describe-flow-logs \
--filter Name=log-destination-type,Values=cloud-watch-logs \
--query 'FlowLogs[].[FlowLogId,ResourceId,LogGroupName]' --output table
aws cloudwatch get-metric-statistics --namespace AWS/Logs --metric-name IncomingBytes \
--dimensions Name=LogGroupName,Value=vpc-flow-logs \
--start-time 2026-08-26T00:00:00Z --end-time 2026-09-25T00:00:00Z \
--period 86400 --statistics Sum

IncomingBytes is the uncompressed volume uploaded to the log group, per the CloudWatch Logs metrics list.

What the rule reads

  1. The VPC has an active VPC-level flow log whose destination type is CloudWatch Logs, with a known log group. Subnet-level and network-interface-level flow logs are not checked.
  2. ZopNight collects the log group’s hourly IncomingBytes sums and scales them to a 30-day month.
  3. The measured volume is at least 1 GB a month.

If several VPCs send flow logs to one shared log group, each VPC is credited with the group’s whole volume, so the same gigabytes are counted once per VPC and the combined saving is overstated.

Flow logs this rule ignores

A VPC whose flow logs already go to S3 is left alone; that is the cheaper destination. A VPC with no flow log, or one where the log group’s ingestion series is missing or zero, produces nothing. The rule never shows a $0 recommendation.

Delivery-rate gap on measured volume

Terminal window
monthly GB = sum of hourly IncomingBytes / 1e9, scaled to 30 days
current cost = monthly GB x $0.50
cost after move = monthly GB x ($0.25 delivery + $0.023 S3 Standard storage)
saving = monthly GB x $0.227

The model uses first-tier us-east-1 rates. Very large volumes that reach lower tiers save less per GB.

Moving flow logs to S3

  1. Create or reuse a log-archive bucket with a bucket policy that allows log delivery.
  2. Create a second flow log with the S3 destination: aws ec2 create-flow-logs --resource-type VPC --resource-ids vpc-0abc1234 --traffic-type ALL --log-destination-type s3 --log-destination arn:aws:s3:::my-flow-log-bucket
  3. Confirm new objects are arriving, then remove the old one: aws ec2 delete-flow-logs --flow-log-ids fl-0abc1234
  4. Query the S3 copy with Amazon Athena, and move any CloudWatch alarms or metric filters built on the old log group first.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·