CloudWatch Logs ingestion vs storage cost: where the money really goes
CloudWatch Logs charges about $0.50 per GB to ingest and only $0.03 per GB per month to store, so ingestion, not retention, is almost always the bigger bill. Understanding the split changes how you cut logging cost. Here is the breakdown.
Quick answer
CloudWatch Logs has two main charges: ingestion at about $0.50 per GB and archival storage at about $0.03 per GB per month. Ingestion is roughly 16 times the monthly storage rate, so the volume of logs you send in, not how long you keep them, drives almost all the cost. Ingesting 1 TB a month costs about $500 in ingestion but only about $30 a month to store. There is also a cheaper Infrequent Access log class at about $0.25 per GB ingestion for logs you rarely query. The lesson: cut what you ingest, because ingestion dwarfs storage, and set retention mainly to avoid unbounded growth.
CloudWatch Logs bills two ways that people constantly confuse, and getting the split wrong leads to optimizing the wrong thing. Ingestion, the charge for sending logs in, is about $0.50 per GB. Storage, the charge for keeping them, is about $0.03 per GB per month. Because ingestion is roughly sixteen times the monthly storage rate, the money is almost entirely in what you send, not what you retain.
The two charges
| Charge | Rate | Applies to |
|---|---|---|
| Ingestion (Standard) | ~$0.50/GB | Every GB sent in |
| Ingestion (Infrequent Access) | ~$0.25/GB | Rarely-queried logs |
| Storage | ~$0.03/GB per month | Retained log data |
Send in 1 TB of logs in a month and you pay about $500 in ingestion. Keep that terabyte for a month and you pay about $30 in storage. The ingestion charge is a one-time hit per GB, while storage recurs monthly, but the rates are so different that even a year of storage ($360) barely exceeds a single month's ingestion. For most workloads, ingestion is the overwhelming majority of the bill.
Why this changes your strategy
If you believe storage dominates, you focus on retention: shortening how long logs are kept. But since ingestion is the real cost, shortening retention from 90 days to 30 saves only storage, a small fraction of the bill. The high-leverage move is reducing what you ingest in the first place: lowering log verbosity, dropping debug logs in production, sampling high-volume logs, and not shipping logs you never read. Cutting ingestion by half cuts roughly half the bill; cutting retention in half cuts only the small storage portion.
Using the Infrequent Access class
For logs you must retain for compliance or occasional investigation but rarely query, the Infrequent Access log class ingests at about $0.25 per GB, half the Standard rate, in exchange for a reduced feature set (no metric filters or live tail, and queries cost more). Routing audit or debug logs you keep but seldom read to this class halves their ingestion cost. Matching each log stream to the right class is a direct saving.
Cutting the ingestion bill
Reduce log verbosity in production, sample or aggregate high-frequency logs, and stop shipping logs nobody queries. Set retention policies so old logs expire rather than accumulating storage forever, which controls the smaller storage charge and keeps log groups tidy. For very high volumes, evaluate whether S3 plus Athena is cheaper than CloudWatch for archival, a common pattern in theCloudWatch Logs optimization guide, and watch for the CloudWatch surprise bill that verbose logging creates.
Because ingestion is the dominant cost and it scales with log volume, the estimate you want is how much your services will emit. Price your logging configuration against theresource catalog so the ingestion cost is understood before the logs start flowing.
FAQ
Is CloudWatch Logs ingestion or storage more expensive?
Ingestion, by far. Ingestion costs about $0.50 per GB while storage is only about $0.03 per GB per month, roughly sixteen times cheaper. Ingesting 1 TB costs about $500 while storing it costs about $30 a month. Even a full year of storage barely exceeds a single month's ingestion, so what you send in, not how long you keep it, drives almost all the cost.
How do I reduce CloudWatch Logs cost?
Focus on ingestion, since it dominates. Reduce log verbosity in production, drop debug logs, sample or aggregate high-volume logs, and stop shipping logs nobody queries. Cutting ingestion in half cuts roughly half the bill. Route rarely-queried logs to the Infrequent Access class at about $0.25 per GB. Set retention policies to control the smaller storage charge, but do not expect retention changes to save much.
What is the CloudWatch Logs Infrequent Access class?
A cheaper log class that ingests at about $0.25 per GB, half the Standard rate, for logs you retain but rarely query. In exchange it has a reduced feature set: no metric filters or live tail, and queries cost more. Routing audit or debug logs you keep for compliance but seldom read to this class halves their ingestion cost with little downside if you rarely query them.
Does shortening log retention save much money?
Not much, because retention only affects the small storage charge of about $0.03 per GB per month, not the dominant ingestion charge of about $0.50 per GB. Shortening retention from 90 to 30 days saves storage on old logs, a fraction of the bill. It is still worth setting retention so logs do not accumulate forever, but the big savings come from ingesting less, not retaining less.
Should I use S3 instead of CloudWatch for logs?
For high-volume archival logs, often yes. S3 storage is far cheaper than CloudWatch storage, and querying with Athena can beat CloudWatch Logs Insights for infrequent analysis. The trade-off is that CloudWatch offers real-time features like metric filters, alarms, and live tail that S3 does not. A common pattern is keeping operational logs in CloudWatch and routing bulk archival logs to S3 for cost.
How does C3X help with CloudWatch Logs cost?
C3X prices your logging configuration from Terraform before you deploy, so the ingestion-driven cost of a verbose or high-volume logging setup is visible in the pull request. Because ingestion dominates and scales with log volume, seeing the estimate at design time helps you set sensible verbosity, choose the Infrequent Access class where appropriate, and avoid the surprise bill from shipping more logs than you read.
What to do next
Estimate your logging cost before it hits the bill. C3X reads your Terraform and prices your resources against a live catalog. Start with the quickstart.
Share this post
Try C3X on your own Terraform
Free and open source. No API key required. One command to install, one command to estimate.