Skip to main content
schedule · azure

Non-production SQL Server VMs moving under 1 GiB of network traffic in 30 days

resource types
1
rule IDs covered
1
severity
low

What does ZopNight detect here?

ZopNight flags a non-production SQL Server on Azure VM when its `Network In Total` and `Network Out Total` add up to less than 1 GiB over 30 days, a sign that almost no client is querying it. Instead of a one-off stop, it recommends a recurring off-hours schedule and prices it from the idle hours it measured.

Signal and threshold

How ZopNight evaluates Non-production SQL Server VMs moving under 1 GiB of network traffic in 30 days.
Field Value
Rule IDsRC-269
Categoryschedule
Severitylow
MetricNetwork In Total, Network Out Total
Thresholdcombined network < 1 GiB in 30 days
Evaluation window30d
SourceZopNight
Permissions usedMicrosoft.SqlVirtualMachine/sqlVirtualMachines/read · Microsoft.Compute/virtualMachines/read · Microsoft.Insights/Metrics/Read

What an unused SQL Server VM keeps charging

A SQL Server VM carries two compute bills: the VM size, and, on pay-as-you-go images, the SQL Server license billed with it. The SQL Server VM pricing guidance is blunt about stopping them: shutting down and deallocating the VM is the only way to avoid charges, and simply stopping it or shutting it down from the guest still incurs usage charges.

Development and test SQL Servers are often built for a project and left running afterwards. Network traffic is a good tell. A database server nobody connects to sends and receives almost nothing, while one in real use moves gigabytes a day.

Measuring network traffic on a SQL Server VM

Terminal window
az sql vm list --query "[].{name:name, rg:resourceGroup, license:sqlServerLicenseType, image:sqlImageSku}" -o table
az monitor metrics list --resource <vm-resource-id> \
--metric "Network In Total" "Network Out Total" \
--aggregation Total --interval PT24H --offset 30d

Add up the daily totals for both directions. Under 1 GiB for the month is the line this rule uses.

Evidence this rule needs

  1. The VM is provisioned successfully and Azure Monitor has network data for it. There is no fallback to a tag; a missing series means no finding.
  2. The VM is positively non-production, from its tags, name or resource group. A VM with no environment signal is not assumed to be non-production.
  3. Network in plus network out over 30 days is under 1 GiB.
  4. ZopNight has measured idle hours for the VM in its activity heatmap, and the VM has a cost.

ZopNight estimates the 30-day total from Azure Monitor’s average per-minute network counters (average x minutes in 30 days), so the figure shown in the recommendation is an estimate, not an exact byte count.

SQL VMs that are not flagged

VMs that already follow a known active schedule are skipped, as are VMs that ZopNight knows have been off for most of the window. Without measured idle hours or a cost, there is nothing to price, so no recommendation appears. For database VMs that are busy but oversized, look at compute rightsizing instead; this rule only addresses near-silent machines.

Schedule saving, not a shutdown

Terminal window
monthly saving = VM monthly cost x measured idle fraction

The lever is a recurring start and stop schedule rather than a single stop, because stopping a running database server indefinitely is an outage, not a cost optimisation. Managed disks keep billing while the VM is deallocated.

Putting the SQL VM on a schedule

  1. Check SQL Server connection logs and recent query activity to confirm nobody depends on it out of hours.
  2. Review the suggested start and stop times in the recommendation.
  3. Apply the schedule, or deallocate outside working hours with az vm deallocate --resource-group my-rg --name my-sql-vm and start it with az vm start.
  4. If the server turns out to be unused altogether, back up the databases and decommission it.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·