How to Read Your AWS Bill: Five Places Spend Hides Outside EC2

How to read your AWS bill by usage type: where NAT Gateway, cross AZ traffic, EBS, CloudWatch Logs and idle load balancer charges appear, and what they mean.

Xplorr team

The people who build Xplorr

7 min read
How to Read Your AWS Bill: Five Places Spend Hides Outside EC2
In this post
  1. How do you see usage types in Cost Explorer?
  2. 1. NAT Gateway: NatGateway-Hours and NatGateway-Bytes
  3. 2. Cross AZ traffic: DataTransfer-Regional-Bytes
  4. 3. EBS volumes and snapshots nobody owns: EBS:VolumeUsage and EBS:SnapshotUsage
  5. 4. CloudWatch Logs: DataProcessing-Bytes and TimedStorage-ByteHrs
  6. 5. Idle load balancers: LoadBalancerUsage
  7. Why do these costs stay hidden?
  8. A faster first pass

Most people read their AWS bill by service: EC2, RDS, S3, and a line called “EC2 - Other” that nobody quite owns. The service view answers “which product”, but it hides the question that matters when you want to cut spend: what is this charge actually for?

The answer lives one level down, in the usage type. Every line on an AWS bill carries one, and it names the thing you are paying for: an hour of a NAT gateway, a gigabyte crossing an availability zone, a gigabyte-month of snapshot storage. Learn to read the bill by usage type and five of the most common hidden costs stop being hidden.

Infographic titled Where AWS spend hides, listing five costs that never show up as EC2: NAT Gateway data processing, cross AZ traffic, unowned EBS volumes and snapshots, CloudWatch Logs ingestion and idle load balancers, each with why it bills and the fix, plus a check this week list: filter Cost Explorer by usage type NatGateway-Bytes, list EBS volumes in the available state, and sort CloudWatch log groups by stored bytes.
Five places AWS spend hides, and the fix for each.

How do you see usage types in Cost Explorer?

Open Cost Explorer, set the range to the last three full months with monthly granularity, and under Group by choose Usage type. Every bar now splits into lines such as USE1-NatGateway-Bytes or EBS:SnapshotUsage. The prefix is the Region code (USE1 is us-east-1, EUC1 is eu-central-1). Lines without one are us-east-1 in many services.

Two filters make the view far more useful:

  • Service = EC2 - Other. This is where NAT gateways, EBS volumes and snapshots, Elastic IPs and most data transfer land. It is often the second largest EC2 line and the least understood.
  • Exclude credits and refunds. A credit can make a costly usage type look free for months, then the credit runs out.

If you have a Cost and Usage Report, the same field is lineItem/UsageType (or line_item_usage_type in CUR 2.0), and it sits next to the resource ID when you have resource IDs switched on.

1. NAT Gateway: NatGateway-Hours and NatGateway-Bytes

A NAT gateway bills twice: by the hour it exists (NatGateway-Hours) and by every gigabyte it processes (NatGateway-Bytes). In us-east-1 both are $0.045, per hour and per GB. The hourly part is small and predictable. The per GB part scales with traffic from private subnets, including traffic to other AWS services such as S3, ECR and DynamoDB.

As an example, a private subnet pulling 5 TB a month from S3 through a NAT gateway pays about $225 in processing alone (5,000 GB x $0.045), on top of the hourly charge. S3 and DynamoDB gateway endpoints are free and take that traffic off the NAT. Interface endpoints for other services have their own hourly and per GB price, so compare them before switching.

2. Cross AZ traffic: DataTransfer-Regional-Bytes

Traffic between availability zones in the same Region shows up as DataTransfer-Regional-Bytes. It costs $0.01 per GB in each direction, so a gigabyte that crosses a zone boundary is billed once leaving and once arriving. Chatty services spread across zones (an API in one, its cache in another, a database replica in a third) add it up quietly.

The fixes are placement and routing: keep chatty pairs in the same zone where availability allows, and in Kubernetes turn on topology aware routing so a Service prefers endpoints in the caller’s zone.

3. EBS volumes and snapshots nobody owns: EBS:VolumeUsage and EBS:SnapshotUsage

Terminate an instance and, unless delete on termination was set, its volumes stay behind in the available state, billing every month. EBS:VolumeUsage.gp3 is $0.08 per GB-month in us-east-1, so a forgotten 500 GB volume is $40 a month for storage nobody reads. Snapshots bill as EBS:SnapshotUsage at $0.05 per GB-month, and old migration or pre upgrade snapshots are easy to forget because nothing breaks when they stay.

Delete unattached volumes after a final snapshot you actually intend to keep, and expire snapshots with Amazon Data Lifecycle Manager rather than by hand.

4. CloudWatch Logs: DataProcessing-Bytes and TimedStorage-ByteHrs

Log ingestion bills under the CloudWatch service as DataProcessing-Bytes, at $0.50 per GB for standard log groups in us-east-1. Storage bills separately as TimedStorage-ByteHrs. One service left on debug logging in production can ingest more in a month than the service itself costs to run.

Set a retention period on every log group (the default is to keep logs forever), drop debug output in production, and filter before shipping rather than after.

5. Idle load balancers: LoadBalancerUsage

A load balancer bills by the hour whether or not it has healthy targets. For an Application Load Balancer that is LoadBalancerUsage at $0.0225 an hour in us-east-1, about $16 a month before any traffic charges. Environments that were torn down often leave their load balancers behind. Look for load balancers with no registered targets or no requests over the last few weeks, confirm with the owner, and delete them.

Prices checked September 2026, us-east-1 list prices. Check your own Region and any discounts you have.

Why do these costs stay hidden?

None of these charges are hard to fix. They stay because of how the bill is presented: grouped by service, most of them fold into “EC2 - Other” or a generic data transfer line, and none of them names the team or the resource behind it. The habit that fixes this is simple. Once a month, group by usage type, sort by cost, and ask who owns the largest line that nobody recognizes.

For a deeper walk through the prices and the network side, see hidden cloud costs you are probably missing. For the CLI commands that turn each finding into a cleanup list, see the AWS cost audit guide.

A faster first pass

If you would rather not build the Cost Explorer view by hand, the free AWS waste finder reads a Cost Explorer CSV grouped by usage type, or a Cost and Usage Report, in your browser. It totals NAT gateway processing, cross AZ transfer, EBS snapshots and the other categories above, and nothing is uploaded.

Xplorr does this continuously once an account is connected with read only access. Network cost splits AWS data transfer into internet egress, inter AZ, cross Region, NAT gateway, VPC endpoint and CDN traffic, by account and by resource. Recommendations flag EC2 instances averaging under 5% CPU over seven days and EBS volumes left unattached. It is free during the private beta.

Keep reading

See how Xplorr helps → Features

ShareLinkedInX

Written by

Xplorr team

The people who build Xplorr

Written together by the engineers who build Xplorr: the AWS, Azure, GCP and Kubernetes collectors, the console, and the alerting behind them.

About Xplorr

Related posts

All articles

Free during the private beta

See your AWS, Azure and GCP spend in one place

Connect a cloud account and find what is driving the bill. Every feature is free while Xplorr is in private beta.