VPC flow logs delivered to CloudWatch Logs at $0.50 per GB when S3 delivery costs $0.25
What does ZopNight detect here?
ZopNight flags VPCs whose flow logs publish to CloudWatch Logs and measures the log group's `IncomingBytes` over 30 days. Vended log delivery to CloudWatch Logs costs $0.50 per GB for the first 10 TB in us-east-1, against $0.25 per GB to S3, so ZopNight prices the switch at that gap minus S3 storage.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-055 |
| Category | rightsizing |
| Severity | low |
| Metric | IncomingBytes (AWS/Logs) |
| Threshold | >= 1 GB per month to a CloudWatch Logs destination |
| Evaluation window | 30d |
| Source | ZopNight |
| Permissions used | ec2:DescribeFlowLogs · cloudwatch:GetMetricStatistics |
Where it applies
Flow logs are billed as vended logs at every destination
VPC Flow Logs are not free to deliver anywhere. The flow logs pricing note says that data ingestion and archival charges for vended logs apply when you publish them, and the S3 destination page repeats that for S3. The difference is the rate. AWS’s price list for US East (N. Virginia) charges $0.50 per GB for the first 10 TB of vended logs ingested into CloudWatch Logs each month and $0.25 per GB for the first 10 TB delivered to S3, with lower tiers above that. The CloudWatch pricing page adds $0.03 per GB for archiving the data in CloudWatch Logs.
A busy VPC can produce hundreds of gigabytes of flow records a month, so the destination choice shows up on the bill.
Measuring what each flow log sends to CloudWatch Logs
aws ec2 describe-flow-logs \ --filter Name=log-destination-type,Values=cloud-watch-logs \ --query 'FlowLogs[].[FlowLogId,ResourceId,LogGroupName]' --output table
aws cloudwatch get-metric-statistics --namespace AWS/Logs --metric-name IncomingBytes \ --dimensions Name=LogGroupName,Value=vpc-flow-logs \ --start-time 2026-08-26T00:00:00Z --end-time 2026-09-25T00:00:00Z \ --period 86400 --statistics SumIncomingBytes is the uncompressed volume uploaded to the log group, per the
CloudWatch Logs metrics list.
What the rule reads
- The VPC has an active VPC-level flow log whose destination type is CloudWatch Logs, with a known log group. Subnet-level and network-interface-level flow logs are not checked.
- ZopNight collects the log group’s hourly
IncomingBytessums and scales them to a 30-day month. - The measured volume is at least 1 GB a month.
If several VPCs send flow logs to one shared log group, each VPC is credited with the group’s whole volume, so the same gigabytes are counted once per VPC and the combined saving is overstated.
Flow logs this rule ignores
A VPC whose flow logs already go to S3 is left alone; that is the cheaper destination. A VPC with no flow log, or one where the log group’s ingestion series is missing or zero, produces nothing. The rule never shows a $0 recommendation.
Delivery-rate gap on measured volume
monthly GB = sum of hourly IncomingBytes / 1e9, scaled to 30 dayscurrent cost = monthly GB x $0.50cost after move = monthly GB x ($0.25 delivery + $0.023 S3 Standard storage)saving = monthly GB x $0.227The model uses first-tier us-east-1 rates. Very large volumes that reach lower tiers save less per GB.
Moving flow logs to S3
- Create or reuse a log-archive bucket with a bucket policy that allows log delivery.
- Create a second flow log with the S3 destination:
aws ec2 create-flow-logs --resource-type VPC --resource-ids vpc-0abc1234 --traffic-type ALL --log-destination-type s3 --log-destination arn:aws:s3:::my-flow-log-bucket - Confirm new objects are arriving, then remove the old one:
aws ec2 delete-flow-logs --flow-log-ids fl-0abc1234 - Query the S3 copy with Amazon Athena, and move any CloudWatch alarms or metric filters built on the old log group first.