Non-production SQL Server VMs moving under 1 GiB of network traffic in 30 days
What does ZopNight detect here?
ZopNight flags a non-production SQL Server on Azure VM when its `Network In Total` and `Network Out Total` add up to less than 1 GiB over 30 days, a sign that almost no client is querying it. Instead of a one-off stop, it recommends a recurring off-hours schedule and prices it from the idle hours it measured.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-269 |
| Category | schedule |
| Severity | low |
| Metric | Network In Total, Network Out Total |
| Threshold | combined network < 1 GiB in 30 days |
| Evaluation window | 30d |
| Source | ZopNight |
| Permissions used | Microsoft.SqlVirtualMachine/sqlVirtualMachines/read · Microsoft.Compute/virtualMachines/read · Microsoft.Insights/Metrics/Read |
Where it applies
What an unused SQL Server VM keeps charging
A SQL Server VM carries two compute bills: the VM size, and, on pay-as-you-go images, the SQL Server license billed with it. The SQL Server VM pricing guidance is blunt about stopping them: shutting down and deallocating the VM is the only way to avoid charges, and simply stopping it or shutting it down from the guest still incurs usage charges.
Development and test SQL Servers are often built for a project and left running afterwards. Network traffic is a good tell. A database server nobody connects to sends and receives almost nothing, while one in real use moves gigabytes a day.
Measuring network traffic on a SQL Server VM
az sql vm list --query "[].{name:name, rg:resourceGroup, license:sqlServerLicenseType, image:sqlImageSku}" -o table
az monitor metrics list --resource <vm-resource-id> \ --metric "Network In Total" "Network Out Total" \ --aggregation Total --interval PT24H --offset 30dAdd up the daily totals for both directions. Under 1 GiB for the month is the line this rule uses.
Evidence this rule needs
- The VM is provisioned successfully and Azure Monitor has network data for it. There is no fallback to a tag; a missing series means no finding.
- The VM is positively non-production, from its tags, name or resource group. A VM with no environment signal is not assumed to be non-production.
- Network in plus network out over 30 days is under 1 GiB.
- ZopNight has measured idle hours for the VM in its activity heatmap, and the VM has a cost.
ZopNight estimates the 30-day total from Azure Monitor’s average per-minute network counters (average x minutes in 30 days), so the figure shown in the recommendation is an estimate, not an exact byte count.
SQL VMs that are not flagged
VMs that already follow a known active schedule are skipped, as are VMs that ZopNight knows have been off for most of the window. Without measured idle hours or a cost, there is nothing to price, so no recommendation appears. For database VMs that are busy but oversized, look at compute rightsizing instead; this rule only addresses near-silent machines.
Schedule saving, not a shutdown
monthly saving = VM monthly cost x measured idle fractionThe lever is a recurring start and stop schedule rather than a single stop, because stopping a running database server indefinitely is an outage, not a cost optimisation. Managed disks keep billing while the VM is deallocated.
Putting the SQL VM on a schedule
- Check SQL Server connection logs and recent query activity to confirm nobody depends on it out of hours.
- Review the suggested start and stop times in the recommendation.
- Apply the schedule, or deallocate outside working hours with
az vm deallocate --resource-group my-rg --name my-sql-vmand start it withaz vm start. - If the server turns out to be unused altogether, back up the databases and decommission it.