Find AWS waste in your Cost Explorer CSV
Drop in a Cost Explorer export or a Cost and Usage Report. The waste finder totals NAT gateway processing, cross AZ and inter Region transfer, EBS snapshots and volumes, CloudWatch Logs, load balancer hours and idle public IPs, ranks them by cost, and says why each one bills and how to reduce it.
Your file never leaves your browser. Nothing is uploaded.
Analyze a cost export
Cost Explorer CSV grouped by Usage type gives the most detail. A legacy CUR or CUR 2.0 file in CSV, plain or .csv.gz, also works and adds service and resource detail.
The sample is synthetic: round made up numbers for an imaginary account.
Private by design. Your file is read by JavaScript in this tab and never leaves your machine. It is not uploaded to Xplorr or anywhere else, and nothing from it is sent to the analytics on this site. Close the tab and it is gone.
What your file shows
Get this every day, with the resources behind it
Xplorr does this continuously across AWS, Azure and GCP, from read only access instead of a one off export. It breaks out network and data transfer costs by service and flags idle EC2 instances and unattached EBS volumes. Free during the beta.
Step by step
How to export the CSV from Cost Explorer
Open Cost Explorer
In the AWS Billing and Cost Management console, choose Cost Explorer.
Pick the period
Set the date range, for example the last three full months, and choose Monthly granularity.
Group by Usage type
Under Group by, choose Dimension, then Usage type. This is what separates NAT gateway, transfer and EBS charges from the rest of EC2.
Download
Choose Download CSV (Download as CSV in the newer console) and drop the file above.
AWS describes the download on its Cost Explorer CSV page.
More detail
Using a Cost and Usage Report instead
A Cost and Usage Report carries the service and, if you enabled resource IDs, the resource for every line. With one, the finder can tell CloudWatch Logs from Classic Load Balancer data processing and lists the resources that cost the most in each category.
Download a CSV or .csv.gz part from the S3 bucket your export writes to. Both the legacy CUR columns (lineItem/UsageType) and CUR 2.0 (line_item_usage_type) are recognised. Parquet exports are not.
Credits, refunds and tax lines are left out of the totals so a credit does not hide a cost. Costs are unblended, the Cost Explorer default.
Method
What the waste finder looks for
Each category is matched on the usage types AWS documents for it, with or without a Region prefix such as USE1. Categories marked check are costs that are often waste but that a billing file alone cannot prove are.
- NAT Gateway data processing
NatGateway-Bytes,EC2: NAT Gateway - Data ProcessedEvery gigabyte that passes through a NAT gateway is billed as processing, on top of any data transfer charge for the same bytes. Traffic from private subnets to S3, ECR, CloudWatch or other AWS services goes through the gateway unless an endpoint gives it another route.
- NAT Gateway hoursCheck
NatGateway-Hours,EC2: NAT Gateway - Running HoursA NAT gateway is billed for every hour it exists, whether or not traffic passes through it. A resilient layout runs one per Availability Zone, and gateways in development or abandoned VPCs keep billing.
- Cross AZ data transfer
DataTransfer-Regional-Bytes,EC2: Data Transfer - Inter AZ,S3: Data Transfer - Inter AZ,RDS: Data Transfer - InterAZTraffic between Availability Zones in one Region is billed per gigabyte, and AWS meters both the sending and the receiving side, so one transfer produces two DataTransfer-Regional-Bytes lines. Chatty services, replicas and load balancers that spread across zones generate it constantly.
- Inter Region data transfer
<source>-<destination>-AWS-Out-Bytes,<region>-AWS-Out-Bytes (VPC peering),EC2: Data Transfer - Region to Region (Out),S3: Data Transfer - Region to Region (Out)Data sent from one Region to another is billed on the sending side. Replication, backups copied to a second Region, and jobs that read data from another Region on every run all add to it.
- Data transfer out to the internetCheck
DataTransfer-Out-Bytes,EC2: Data Transfer - Internet (Out),S3: Data Transfer - Internet (Out)Bytes leaving AWS for the internet are billed per gigabyte. It grows with downloads, API responses and anything served straight from EC2, S3 or a load balancer rather than through a cache.
- EBS snapshot storageCheck
EBS:SnapshotUsage,EBS:SnapshotArchiveStorage,EC2: EBS - SnapshotsSnapshots are billed per GB-month for as long as they exist. Automated backups without a retention rule, and snapshots of volumes that were deleted long ago, keep adding to the total.
- EBS volume storageCheck
EBS:VolumeUsage.gp3,EBS:VolumeUsage.gp2,EBS:VolumeUsage.io2,EBS:VolumeUsage.piops,EBS:VolumeUsage.st1,EBS:VolumeUsage.sc1,EBS:VolumeUsage,EC2: EBS - SSD(gp2),EC2: EBS - SSD(io1),EC2: EBS - MagneticVolumes are billed on provisioned size, not on what is written to them, and they keep billing when detached. An unattached volume left behind by a terminated instance costs the same as one in use.
- EBS provisioned IOPS and throughputCheck
EBS:VolumeP-IOPS.gp3,EBS:VolumeP-Throughput.gp3,EBS:VolumeP-IOPS.io2,EBS:VolumeP-IOPS.piops,EC2: EBS - Provisioned IOPSIOPS and throughput above the baseline are billed per month whether or not the volume ever uses them. Values set during a load test or a migration are rarely turned back down.
- CloudWatch Logs ingestion
DataProcessing-Bytes (CloudWatch),DataProcessingIA-Bytes,VendedLog-Bytes,VendedLogIA-BytesCloudWatch Logs bills every gigabyte written to a log group. Debug logging left on in production, verbose access logs and VPC flow logs sent to CloudWatch are the usual sources.
- Logs ingestion or Classic Load Balancer data (service unknown)Check
DataProcessing-BytesAWS uses DataProcessing-Bytes for two different charges: CloudWatch Logs ingestion and data processed by Classic Load Balancers. A Cost Explorer export grouped only by usage type does not say which service a line belongs to.
- CloudWatch Logs storageCheck
TimedStorage-ByteHrs (CloudWatch),TimedStorage-IA-ByteHrs,TimedStorage-AIA-ByteHrsLog groups keep data forever unless a retention period is set, and stored logs are billed per GB-month.
- Load balancer hoursCheck
LoadBalancerUsage,EC2: ELB - Running HoursEvery Application, Network, Gateway and Classic Load Balancer is billed for each hour it exists, with or without traffic. Load balancers created for a test, a preview environment or a service that was retired keep billing.
- Reserved load balancer capacity not used
IdleProvisionedLBCapacityAWS documents this usage type as load balancer capacity units that were reserved but not used.
- Idle public IPv4 addresses
PublicIPv4:IdleAddress,EC2: Elastic IP - Idle AddressA public IPv4 address that is allocated but not in use, such as an Elastic IP attached to nothing, is billed by the hour.
- In use public IPv4 addressesCheck
PublicIPv4:InUseAddressEvery public IPv4 address attached to an instance, load balancer or other resource is billed by the hour, including the ones assigned automatically at launch.
Usage type names from AWS documentation fordata transfer,EBS,Elastic Load Balancing,CloudWatchandCost Explorer usage type groups.
Questions about the AWS waste finder
Is my cost file uploaded anywhere?
Which AWS files can it read?
Why does it not tell me how much I can save?
Why is NAT Gateway cost hard to find in Cost Explorer?
Why is some DataProcessing-Bytes cost marked as service unknown?
Does a load balancer in the results mean it is idle?
What does Xplorr do beyond this tool?
Related reading
Hidden cloud costs you are missing
NAT gateway processing, cross AZ transfer, idle load balancers and log ingestion, priced at list.
Network costs in Xplorr
Data transfer split into internet egress, cross Region, inter AZ, VPN and peering across three clouds.
Recommendations in Xplorr
Idle EC2 instances and unattached EBS volumes, each with the evidence behind it.
Stop exporting CSVs to find this
Xplorr does this continuously across AWS, Azure and GCP, with resource detail. It breaks out network and data transfer costs by service and flags idle EC2 instances and unattached EBS volumes. Read only access, free during the beta.