Azure AI Search services on dedicated capacity that answered zero queries
What does ZopNight detect here?
ZopNight flags an Azure AI Search service whose `SearchQueriesPerSecond` metric reads exactly zero on both average and peak, with at least 7 days of data and a known monthly cost. On the Dedicated pricing model a search service bills every hour for its replicas and partitions, and Microsoft states that only deleting the service stops billing entirely.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1398 |
| Category | idle |
| Severity | medium |
| Metric | SearchQueriesPerSecond |
| Threshold | average and maximum = 0 |
| Evaluation window | 30d |
| Source | ZopNight |
| Permissions used | Microsoft.Search/searchServices/read · Microsoft.Insights/Metrics/Read |
Where it applies
Search units bill whether or not anyone searches
On the Dedicated pricing model, an Azure AI Search service is provisioned capacity: you pay the tier’s prorated hourly rate for every replica and partition combination, known as search units, from the moment it exists. That base charge does not depend on traffic, so a service that nobody queries pays the same hourly rate as a busy one of the same size.
Microsoft is direct about the way out: to stop billing entirely on Dedicated you must delete the service, and deletion also removes its data.
Checking query traffic on a search service
az search service list --resource-group my-rg \ --query "[].{name:name, sku:sku.name, replicas:replicaCount, partitions:partitionCount}" -o table
az monitor metrics list --resource <search-service-resource-id> \ --metric SearchQueriesPerSecond --offset 30d --interval PT24H --aggregation Average MaximumEvery daily average and maximum at zero means no queries reached the service in that period.
The four conditions behind the finding
- The
SearchQueriesPerSecondseries exists for the service. - Its average is exactly 0 and its maximum is exactly 0. Any query at all ends the check.
- The series covers at least 7 days, so a service created last week and still being wired up is not told to delete itself.
- The service has a known monthly cost above zero.
Unit count does not matter here: a single-replica, single-partition service qualifies just as a large one does.
Cases that do not count as idle
A missing metric is not treated as zero. If Azure Monitor has no query series for the service, there is no finding. Low but non-zero traffic is also out of scope; a service with more than one search unit and very little traffic is handled by Azure AI Search Over-Provisioned, which suggests fewer units rather than deletion.
Saving equals the whole service cost
saving = current monthly cost of the search servicecost after fix = 0The cost is the tier’s hourly rate multiplied by the number of search units. Deleting the service recovers all of it.
Retiring an unused search service
- Search application code, configuration and indexers for the service endpoint to confirm nothing calls it.
- Export the index definitions, and the source data location, needed to rebuild it later.
- Delete it:
az search service delete --resource-group my-rg --name my-search. - If you need search again for occasional or bursty use, consider the Serverless model (in preview), which Microsoft suggests can cost less than a continuously provisioned Basic or S1 service.