CostMonStart free

AWS bill line item

PaidEventsAnalyzed-Bytes

GuardDuty's charge for the volume (in GB) of network flow and DNS query log data it analyzes each month, billed on a tiered per-GB schedule after any free-trial allowance.

Security & keysAmazon GuardDuty

GuardDuty log analysis, per GB

Verified against official AWS documentation last checked

Why it shows up

This scales directly with network traffic volume, so it grows with egress/ingress and DNS query volume: busy NAT gateways, chatty microservices, or a sudden traffic spike all drive more log data into GuardDuty for analysis.

New accounts or newly-enabled detectors get a free trial period, so the charge can appear to jump sharply once that trial ends even though traffic hasn't changed.

How to cut it

  • Use GuardDuty's own usage statistics to identify which accounts or regions are contributing the most analyzed bytes.
  • Reduce unnecessary network chatter feeding the underlying logs (tighten security groups, reduce noisy health-check or discovery traffic) rather than disabling the logs themselves.
  • Take advantage of the built-in volume-tiered discount; consolidating accounts into an organization-wide setup can shift usage into cheaper tiers.
  • Don't disable GuardDuty to save cost; instead confirm it's only enabled where needed, not duplicated across redundant member accounts.

How to read a usage type

PaidEventsAnalyzed-Bytes carries no region or direction token, so there's nothing to break down here.

Found PaidEventsAnalyzed-Bytes on your own bill?

Drop your Cost Explorer CSV into the AWS Bill Analyzer. It'll flag line items like this one on your own bill and link straight back to the fix.

Analyze your own bill →

A bill read by hand goes stale tomorrow.

Reading one export line by line takes real work. CostMon reads the next one for you, every day, for every provider you connect.

Esc