AWS GuardDuty cost explained: per GB and per event analyzed
GuardDuty bills by the volume of logs and events it analyzes, CloudTrail events, VPC flow logs, DNS logs, and per feature (S3, EKS, malware, RDS protection). High-traffic accounts and enabled features drive the bill. Here is the model.
Quick answer
GuardDuty bills by the volume of data it analyzes: per million CloudTrail events, per GB of VPC flow logs and DNS logs, plus separate per-feature charges for S3 protection, EKS protection, malware protection, and RDS protection. Cost scales with account activity and which protection features you enable, so enabling the features you need (not all) and being aware that high-traffic accounts cost more are the levers.
Amazon GuardDuty is a threat-detection service that continuously analyzes AWS logs and events for malicious activity. Its cost is driven by the volume of data it analyzes and which optional protection features you turn on, so busy accounts and many enabled features cost more.
Per volume analyzed, plus features
| Source / feature | Bills for |
|---|---|
| CloudTrail events | Per million events analyzed |
| VPC flow logs + DNS logs | Per GB analyzed |
| S3 / EKS / malware / RDS protection | Separate per-feature charges |
The core GuardDuty charge is per million CloudTrail management events and per gigabyte of VPC flow logs and DNS logs analyzed, so a high-activity, high-traffic account generates more. Optional protection features (S3 protection, EKS runtime, malware protection scanning, RDS protection) each add their own usage-based charge when enabled. So the bill is core analysis plus the features you turn on.
What drives the bill
Account activity (CloudTrail event volume, network traffic generating flow logs) drives the core cost, and enabled features drive the rest. A busy, high-traffic multi-account organization with all protection features enabled costs the most. The value is threat detection across the account, which for most is worth the usage-based cost.
Controlling GuardDuty cost
Enable the protection features you actually need for your workloads rather than all of them by default (malware and EKS protection add cost that only matters if you run those), review the cost per feature against its value, and understand that high-traffic accounts cost more because there is more to analyze. GuardDuty is usually worth its cost for the detection it provides; the discipline is enabling features purposefully, the same scoped-enablement principle as Security Hub.
FAQ
How is AWS GuardDuty priced?
By the volume of data it analyzes: per million CloudTrail events, per GB of VPC flow logs and DNS logs, plus separate per-feature charges for S3 protection, EKS protection, malware protection, and RDS protection. Cost scales with account activity and which protection features you enable.
How do I reduce GuardDuty cost?
Enable the protection features you actually need for your workloads rather than all of them by default (malware and EKS protection add cost that only matters if you run those), review each feature's cost against its value, and understand high-traffic accounts cost more because there is more to analyze. Purposeful feature enablement is the main lever.
What drives GuardDuty cost?
Account activity, CloudTrail event volume and network traffic generating flow logs, drives the core analysis cost, and enabled protection features drive the rest. A busy, high-traffic organization with all features enabled costs the most, while a quieter account with only core detection costs less.
Do GuardDuty protection features cost extra?
Yes. The optional features, S3 protection, EKS runtime protection, malware protection scanning, and RDS protection, each add their own usage-based charge when enabled, on top of the core CloudTrail and flow-log analysis. So enable the ones relevant to your workloads (malware and EKS only matter if you run those) rather than all by default.
Is GuardDuty worth the cost?
For most accounts, yes. It provides continuous threat detection across AWS activity that would be hard to replicate, and its usage-based cost scales with what it analyzes. The discipline is enabling protection features purposefully rather than all by default, so you pay for the detection relevant to your workloads.
Does C3X estimate GuardDuty cost?
GuardDuty cost is driven by log and event volume analyzed, which are usage inputs tied to account activity. C3X prices the surrounding infrastructure, and you model your CloudTrail, flow-log, and DNS-log volumes plus enabled features to estimate the threat-detection charges.
What to do next
Estimate your security-monitoring infrastructure before you deploy. C3X reads your Terraform and prices your resources against a live catalog. Start with the quickstart.
Share this post
Try C3X on your own Terraform
Free and open source. No API key required. One command to install, one command to estimate.