What the log anomaly spotter costs
The compute here is trivial and the log ingestion is not. Two million lines a week is a small serverless system with sensible logging; fifty million is one with debug logging left on. Here is where each cent goes.
Key takeaways
- About $6 a month at 10M lines. Roughly $26 at 50M lines.
- One Bedrock read per million lines is the only line that scales. Everything else is rounding.
- Nothing is always-on, so a quiet month genuinely costs almost nothing.
- Log ingestion is the dominant cost and it is charged whether or not anything reads the logs. This system makes them worth what you are already paying.
- The duplicate test runs before the read, so resends are free.
- The three real risks: a retry loop, storage nobody expires, and a bigger model than the job needs.
The bill at three volumes
These are US East prices at the time of writing, at three volumes that bracket most small businesses. Find the bar closest to your own and read across.
Line by line
| Line | At 10M lines | How it scales |
|---|---|---|
| Bedrock read | $0.00 | Linear. One call per million lines, roughly 1,800 in and 200 out tokens. |
| CloudWatch Logs ingestion | $5.00 | Linear at $0.5000 per million lines. |
| SES | $0.04 | Linear. About 30 messages per million lines. |
| DynamoDB + S3 | $0.28 | Storage grows with what you retain, not with throughput. |
| Lambda + SQS | $0.12 | Linear, and effectively free at this scale. |
| CloudWatch | $0.16 | Flat, if you set retention. Unbounded if you do not. |
| Secrets Manager | $0.40 | Flat. One secret, $0.40 a month. |
| AWS Budgets | $0.46 | Flat. Two actions, so you find out before the bill does. |
The ingestion band is what you already pay for having logs at all; it appears here because it dominates and because this system is frequently the thing that makes somebody look at it. The processing itself is a few cents.
The three ways this bill surprises you
Every one of these has happened to somebody, and all three are cheap to prevent.
- Debug logging left on in production. The single largest cost risk here, and it is not caused by this system — it multiplies ingestion by ten or more and this system is what will finally make somebody notice.
- Fingerprinting every line in a Lambda. At fifty million lines a week, processing every line individually is real compute. Aggregate in the subscription filter’s batch and fingerprint per batch.
- Log retention left at never. Storage compounds on top of ingestion, and logs older than a few weeks have no value to this system at all — the baselines only look back four weeks.
What it costs when nothing happens
This matters more than the headline number for a seasonal business. In a month with nothing to process the bill is the fixed band: Secrets Manager at forty cents, AWS Budgets at forty-six, and a few cents of storage. Call it a dollar. There is no instance to stop and nothing to remember to turn off.
- Management
- Analytics
- Front-end & mobile
Set these on day one
- A dead-letter queue on every SQS queue, with a maximum receive count of three.
- Thirty-day retention on every CloudWatch log group. There is no default that is safe.
- An S3 lifecycle rule on the object prefix, tiering at 90 days and expiring at your actual record-keeping horizon.
- Two AWS Budgets actions — one that emails at half your expected spend, one at double it. The second is how you find out about a loop in an hour instead of a month.
- Provisioned concurrency: none. Nothing here is latency-sensitive enough to justify paying for a warm function.
Next: the same system drawn for engineers — service names, resource identifiers, IAM scopes, table schemas and the model id.
All posts