awsguarddutysecuritycost-optimization

AWS GuardDuty cost: priced by the volume it analyzes

GuardDuty bills by the data it inspects: CloudTrail events, VPC Flow Logs, DNS logs, and optional S3, EKS, and malware protection. High-volume accounts pay the most. Here is what drives the bill and how to control it.

The C3X Team··5 min read

Quick answer

GuardDuty bills by the volume of data it analyzes: CloudTrail management events (per million), VPC Flow Logs and DNS logs (per GB, tiered), plus optional S3 protection, EKS audit logs, and malware scanning, each priced separately. High-activity accounts pay the most, so the levers are which protections you enable and reducing the underlying event and log volume.

GuardDuty is a threat-detection service that continuously analyzes your account activity. You do not pay for the service directly; you pay for the volume of data it inspects, so the bill scales with how busy and how large your accounts are.

The core data sources

SourceBilling
CloudTrail management eventsPer million events, tiered
VPC Flow LogsPer GB analyzed, tiered
DNS query logsPer GB analyzed, tiered

These three are the foundation of GuardDuty and scale with account activity and network traffic. A high-throughput, chatty account generates many CloudTrail events and large flow-log volumes, which is where most of the bill comes from.

Optional protections add lines

S3 protection, EKS audit-log monitoring, RDS protection, Lambda protection, and malware scanning are each additional, separately-priced features. They add coverage and cost, so enable the ones your threat model needs rather than all of them by default. Malware scanning in particular is priced by the volume of data scanned.

Controlling GuardDuty cost

Enable the protections that match your risk, not every feature. Reduce the underlying volume where you can, since noisy CloudTrail activity and large flow-log volumes drive the core charge. Use the free trial and the cost estimate GuardDuty provides to size the bill before committing across an organization, and apply it consistently through AWS Organizations so coverage and cost are predictable rather than surprising per account.

FAQ

How is AWS GuardDuty priced?

By the volume of data it analyzes: CloudTrail management events per million, VPC Flow Logs and DNS logs per GB (both tiered), plus optional S3, EKS, RDS, Lambda, and malware protections priced separately. There is no flat service fee; cost scales with activity.

What drives GuardDuty cost?

Account activity and network volume. Busy accounts generate many CloudTrail events, and high-traffic VPCs produce large flow-log volumes, which are the core billed data sources. High-activity, large accounts pay the most.

How do I reduce GuardDuty cost?

Enable only the optional protections your threat model needs rather than all of them, reduce noisy CloudTrail activity and flow-log volume where possible, and use GuardDuty's cost estimate and free trial to size the bill before rolling it out across an organization.

Do the optional GuardDuty protections cost extra?

Yes. S3 protection, EKS audit-log monitoring, RDS and Lambda protection, and malware scanning are each additional, separately-priced features on top of the core CloudTrail, flow-log, and DNS analysis. Enable the ones your risk profile justifies.

Is GuardDuty worth the cost?

For most production environments, yes, as managed threat detection that would be expensive to build and operate yourself. The way to keep it economical is enabling the protections that match your threat model rather than every feature everywhere.

Does C3X estimate GuardDuty cost?

GuardDuty cost is driven by analyzed data volume, a usage input tied to account activity. C3X prices the surrounding infrastructure, and you model event and log volume to estimate the analysis charges.

What to do next

Estimate the infrastructure around your security tooling before you deploy. C3X reads your Terraform and prices your resources against a live catalog. Start with the quickstart.

Try C3X on your own Terraform

Free and open source. No API key required. One command to install, one command to estimate.