High GuardDuty costs involving CloudTrail

0

Hello,

I have been receiving a high cost from GuardDuty every day for some time, when I analyzed it further I saw that this cost is related to the analysis of CloudTrail events by GuardDuty, and I noticed that there is a huge amount of events generated in the Staging environment that was also happening We did the same thing by deleting a track that was inactive and this resulted in an improvement in costs, but in the production environment we did not have the same result.

I would like to know how I can check why so many events are being generated and also how to disable this analysis to reduce the cost.

2개 답변
1

Besides getting the cost reviewed through support case, here are some ways that you can use to reduce CloudTrail and GuardDuty costs:

  • CloudTrail cost is based on the number of events in the CloudTrail trail you created, so removing the unused trails should help reduce the cost in both staging and production account to some extent. I suggest you use Cost Explore to view the detailed CloudTrail cost and usage. Here is a reference article that you can refer to: Why did my CloudTrail cost and usage increase unexpectedly?.
  • AWS has a best-practice document (Managing CloudTrail trail costs) that can be used to optimize the CloudTrail trail cost, you can take a look if you have not.

GuardDuty cost is closely related to the workload in your AWS environment and the number of protections you enabled. Here are some possible ways to reduce GuardDuty cost:

  • Besides using the above way to reduce the CloudTrail cost, enabling GuardDuty only in accounts and regions that have active workloads (or have critical workloads if more cost reduction is needed) can help.
  • GuardDuty have optional protections (S3, EKS, RDS etc.), you can check if any of them are enabled and disable the protections that are not required. CloudTrail logs and events are foundational data sources for GuardDuty so there is no option to stop GuardDuty from processing CloudTrail logs and events.

Hope the above suggestions can help you lowe the cost.

Jasenc
답변함 3달 전
0

Hello,

Sorry to hear about the trouble with this. I'd recommend reaching out to our Billing team for further assistance. You can open a case, in our Support Center: go.aws/support-center:

— Ann D.

profile pictureAWS
전문가
답변함 5달 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠