Skip to content

Part 6 of 7 · Log anomaly spotter series ~5 min read

What the log anomaly spotter costs

The compute here is trivial and the log ingestion is not. Two million lines a week is a small serverless system with sensible logging; fifty million is one with debug logging left on. Here is where each cent goes.

Key takeaways

  • About $6 a month at 10M lines. Roughly $26 at 50M lines.
  • One Bedrock read per million lines is the only line that scales. Everything else is rounding.
  • Nothing is always-on, so a quiet month genuinely costs almost nothing.
  • Log ingestion is the dominant cost and it is charged whether or not anything reads the logs. This system makes them worth what you are already paying.
  • The duplicate test runs before the read, so resends are free.
  • The three real risks: a retry loop, storage nobody expires, and a bigger model than the job needs.

The bill at three volumes

These are US East prices at the time of writing, at three volumes that bracket most small businesses. Find the bar closest to your own and read across.

Monthly cost of the log anomaly spotter at three volumesA stacked bar chart with three bars, one per volume tier: 2M lines totalling about $2, 10M lines totalling about $6, and 50M lines totalling about $26. Each bar is stacked from bands. The largest and fastest-growing is Bedrock, one read per million lines, in teal. Then SES for the messages, in pink. Then S3 and DynamoDB storage in green. Then a fixed orange band for Secrets Manager and AWS Budgets, which is eighty-six cents at every volume. Then a grey band for Lambda, SQS and CloudWatch. A note says the read is the only bar that grows with the business and the orange band never moves.$0$10$20$30$40~$2.252M lines~$6.2910M lines~$26.4650M linesBedrock — one read per million linesSES — asks, results, receiptsCloudWatch Logs ingestionS3 + DynamoDBFixed — Secrets Manager, BudgetsLambda, SQS, CloudWatchThe read is the only bar that grows with the business. The orange fixed band never moves.
Fig 1. The monthly bill at three volumes. The teal band — one model read per million lines — is the only part that grows; the orange fixed band is the same 86 cents at every volume.

Line by line

LineAt 10M linesHow it scales
Bedrock read$0.00Linear. One call per million lines, roughly 1,800 in and 200 out tokens.
CloudWatch Logs ingestion$5.00Linear at $0.5000 per million lines.
SES$0.04Linear. About 30 messages per million lines.
DynamoDB + S3$0.28Storage grows with what you retain, not with throughput.
Lambda + SQS$0.12Linear, and effectively free at this scale.
CloudWatch$0.16Flat, if you set retention. Unbounded if you do not.
Secrets Manager$0.40Flat. One secret, $0.40 a month.
AWS Budgets$0.46Flat. Two actions, so you find out before the bill does.

The ingestion band is what you already pay for having logs at all; it appears here because it dominates and because this system is frequently the thing that makes somebody look at it. The processing itself is a few cents.

The three ways this bill surprises you

Every one of these has happened to somebody, and all three are cheap to prevent.

  • Debug logging left on in production. The single largest cost risk here, and it is not caused by this system — it multiplies ingestion by ten or more and this system is what will finally make somebody notice.
  • Fingerprinting every line in a Lambda. At fifty million lines a week, processing every line individually is real compute. Aggregate in the subscription filter’s batch and fingerprint per batch.
  • Log retention left at never. Storage compounds on top of ingestion, and logs older than a few weeks have no value to this system at all — the baselines only look back four weeks.

What it costs when nothing happens

This matters more than the headline number for a seasonal business. In a month with nothing to process the bill is the fixed band: Secrets Manager at forty cents, AWS Budgets at forty-six, and a few cents of storage. Call it a dollar. There is no instance to stop and nothing to remember to turn off.

The monthly bill at four volumes plus one failure modeA horizontal row of five boxes. Quiet month, about one dollar. 2M lines, about $2. 10M lines, about $6. 50M lines, about $26. And one bad retry loop, about two hundred dollars. A note says four of these are the design working and the fifth is a missing dead-letter queue.THE BILL, AT A GLANCEQuiet month~$12M lines~$210M lines~$650M lines~$26One bad loop~$200Four of these are the design working. The fifth is a missing dead-letter queue.
Fig 2. The bill at a glance, including the one that is not a volume at all. A retry loop with no dead-letter queue costs more than every legitimate use of the system put together.
  • Management
  • Analytics
  • Front-end & mobile

Set these on day one

  • A dead-letter queue on every SQS queue, with a maximum receive count of three.
  • Thirty-day retention on every CloudWatch log group. There is no default that is safe.
  • An S3 lifecycle rule on the object prefix, tiering at 90 days and expiring at your actual record-keeping horizon.
  • Two AWS Budgets actions — one that emails at half your expected spend, one at double it. The second is how you find out about a loop in an hour instead of a month.
  • Provisioned concurrency: none. Nothing here is latency-sensitive enough to justify paying for a warm function.

Next: the same system drawn for engineers — service names, resource identifiers, IAM scopes, table schemas and the model id.

All posts