CostMonStart free

AWS bill line item

VendedLog-Bytes

The per-GB charge for logs that other AWS services generate and deliver into CloudWatch Logs on your behalf (VPC flow logs, DNS query logs, CDN logs, WAF logs), billed separately from logs your own code writes.

Observability & managementAmazonCloudWatch

CloudWatch vended logs

Verified against official AWS documentation last checked

Why it shows up

VPC flow logs in particular can generate enormous, continuous volume once enabled across every network interface in a busy VPC, and it's common to turn them on for a single investigation and forget to turn them back off.

Vended logs are priced and tracked separately from custom application logs, so a spike here points specifically at an AWS-managed logging feature rather than your own application code.

How to cut it

  • Scope flow logs to specific interfaces, subnets, or traffic types instead of an entire VPC.
  • Turn flow logs off once a troubleshooting window ends rather than leaving them running indefinitely.
  • Send high-volume vended logs to cheaper storage instead of CloudWatch Logs if you only need them for audit/compliance, not live queries.
  • Use an infrequent-access log class for vended logs you rarely query interactively.

How to read a usage type

VendedLog-Bytes carries no region or direction token, so there's nothing to break down here.

Found VendedLog-Bytes on your own bill?

Drop your Cost Explorer CSV into the AWS Bill Analyzer. It'll flag line items like this one on your own bill and link straight back to the fix.

Analyze your own bill →

The invoice is a lagging signal.

A monthly invoice tells you what already happened. CostMon builds a daily baseline, so a spike stands out while you can still act on it.

Esc