CloudWatch vs third-party APM: comparing the cost models honestly
One bills per metric, log GB, and alarm. The other bills per host and per seat. They cross over at predictable points, and the crossover depends more on your fleet shape than on your traffic. Here is where each wins.
Quick answer
CloudWatch bills usage meters: $0.30 per custom metric-month, $0.50 per GB of log ingestion, $0.10 per alarm-month, $0.005 per GB of Logs Insights scanned, $5.00 per million X-Ray traces. Third-party APM typically bills per host: roughly $15 per host-month for infrastructure and $31 per host-month for APM, plus per-GB log ingestion around $0.10 with separate indexing charges. The crossover is fleet-shaped: CloudWatch wins on large fleets of lightly instrumented hosts, per-host APM wins on small fleets generating heavy telemetry. A 500-host fleet at $31 is $15,500 regardless of how little you send.
The comparison people usually run is "what does our CloudWatch bill look like versus a vendor quote", and it produces the wrong answer because the two models respond to completely different inputs. CloudWatch scales with telemetry volume and is indifferent to how many machines produced it. Per-host APM scales with machine count and is largely indifferent to volume. Your architecture decides which one is punishing.
The two price sheets
| Meter | CloudWatch | Typical per-host APM |
|---|---|---|
| Infrastructure monitoring | $0.30 / custom metric-month | ~$15 / host-month |
| APM and tracing | $5.00 / M traces (X-Ray) | ~$31 / host-month |
| Log ingestion | $0.50 / GB | ~$0.10 / GB ingest |
| Log indexing / retention | $0.03 / GB-month | ~$1.70 to $2.50 / M events, 15 days |
| Alarms | $0.10 each / month | usually included |
| Dashboards | $3.00 each / month over 3 | usually included |
| Seats | free | often per-seat for some modules |
Two structural differences jump out. CloudWatch charges nothing for users and quite a lot for log ingestion. Per-host APM does the reverse: cheap ingestion, expensive hosts, and features bundled into the host price that CloudWatch meters individually.
Scenario one: large fleet, light telemetry
A batch-processing estate with 600 EC2 instances, standard CPU and disk metrics only, 15 GB/day of logs, and 80 alarms. On CloudWatch the built-in EC2 metrics are free at 5-minute resolution; detailed 1-minute monitoring costs $2.10 per instance per month, or $1,260 for the fleet. Logs are 450 GB per month at $0.50, so $225. Alarms are $8. Three dashboards are free, the next five cost $15. Total roughly $1,508.
The per-host quote for 600 hosts at $15 for infrastructure monitoring is $9,000 before anyone sends a log line. That is six times CloudWatch for a workload that generates almost no telemetry. Large fleets of boring machines are where CloudWatch is simply the correct answer.
Scenario two: small fleet, heavy telemetry
A container platform running 40 nodes, 220 GB/day of logs, 45,000 custom metrics, heavy tracing at 200 million spans per month, and 400 alarms. CloudWatch: 45,000 custom metrics costs $3,000 for the first 10,000 plus $3,500 for the next 35,000, so $6,500. Logs at 6,600 GB per month cost $3,300 in ingestion plus $198 in storage. X-Ray at 20 million traces is $100. Alarms are $40. Logs Insights queries, if teams scan 500 GB per day across dashboards and investigations, add $75. Total roughly $10,213.
The per-host quote for 40 hosts at $31 for full APM is $1,240, plus log ingestion at 6,600 GB times $0.10 which is $660, plus indexed log events. If those 220 GB/day are 400 million events per month and you index a tenth of them at $2.00 per million, that is $80. Total roughly $1,980, five times cheaper than CloudWatch. Dense, chatty workloads on few hosts are where per-host pricing is a bargain.
Where the crossover sits
| Shape | Cheaper model |
|---|---|
| More than ~150 hosts, under 20 GB/day logs | CloudWatch |
| Under ~60 hosts, over 100 GB/day logs | Per-host APM |
| Serverless-dominant (Lambda, Fargate) | Depends on host definition |
| Thousands of custom metrics | Per-host APM |
| Very few custom metrics, mostly built-ins | CloudWatch |
The serverless row deserves attention because it is where per-host pricing gets strange. Vendors define a host differently for Fargate tasks, Lambda functions, and Kubernetes pods, sometimes counting containers as fractional hosts, sometimes billing Lambda per invocation instead. A platform running 3,000 short-lived Fargate tasks per day can produce a host count that bears no relation to steady-state capacity, and the contract language on this is worth reading carefully before signing. Meanwhile CloudWatch prices Lambda telemetry purely on the logs and metrics it produces, which is predictable if not always cheap. See the broader monitoring comparison for the full grid.
The hidden CloudWatch meters
CloudWatch's individually metered features are how a modest-looking bill becomes a surprise. Custom metrics at $0.30 each add up fast when a library emits per-instance dimensions. Logs Insights at $0.005 per GB scanned turns an auto-refreshing dashboard into a recurring charge. Contributor Insights is $0.50 per rule-month plus $0.02 per million events. Synthetics canaries are $0.0012 per run, which is $51.84 per month for a canary at one-minute frequency. High-resolution alarms are $0.30 rather than $0.10. None of these are large alone.
The practical answer for most teams
It is usually both. CloudWatch is not optional on AWS: service metrics, Lambda logs, and load balancer logs land there whether you want them or not, so you pay some CloudWatch bill regardless. The design question is how much of it you forward onward. A common shape is CloudWatch as the collection layer with metric filters and subscription filters routing a curated subset to a third-party platform for the services that need deep APM, leaving batch and background fleets on CloudWatch alone.
Watch the forwarding cost when you do this: a Kinesis Data Firehose subscription filter charges $0.029 per GB for the first 500 TB per month, and cross-account or cross-region forwarding adds data transfer at $0.02 or $0.09 per GB. Forwarding 6,600 GB per month costs about $191 in Firehose alone, before egress. Price the forwarding infrastructure from Terraform against the resource catalog so the connective tissue between the two platforms is in the estimate rather than discovered later.
FAQ
Is CloudWatch cheaper than a third-party APM?
It depends on fleet shape, not traffic. For 600 lightly instrumented instances with 15 GB/day of logs, CloudWatch costs roughly $1,508 per month versus $9,000 for per-host infrastructure monitoring at $15 per host. For 40 nodes generating 220 GB/day of logs and 45,000 custom metrics, CloudWatch costs about $10,213 versus roughly $1,980 for a per-host APM. Many hosts and little telemetry favors CloudWatch; few hosts and heavy telemetry favors per-host pricing.
What are the main CloudWatch cost meters?
Custom metrics at $0.30 each per month for the first 10,000, log ingestion at $0.50 per GB with storage at $0.03 per GB-month, Logs Insights queries at $0.005 per GB scanned, alarms at $0.10 each ($0.30 high-resolution), dashboards at $3.00 each beyond three, X-Ray traces at $5.00 per million, Contributor Insights at $0.50 per rule plus $0.02 per million events, and Synthetics canaries at $0.0012 per run.
How does per-host APM pricing work?
Typically around $15 per host-month for infrastructure monitoring and $31 per host-month for full APM, with log ingestion around $0.10 per GB and indexed log events billed separately at roughly $1.70 to $2.50 per million for 15-day retention. Dashboards, alerting, and most features are bundled into the host price. The charge is largely independent of how much telemetry each host produces, which is what creates the crossover against usage-based pricing.
How does serverless affect the comparison?
It is the least predictable area. Vendors define a host differently for Fargate tasks, Lambda functions, and Kubernetes pods, sometimes counting containers as fractional hosts and sometimes billing Lambda per invocation. A platform running 3,000 short-lived Fargate tasks per day can generate a host count unrelated to steady-state capacity. CloudWatch prices serverless telemetry purely on logs and metrics produced, which is predictable even when it is not cheap.
Can I use CloudWatch and a third-party platform together?
Most AWS teams do, because CloudWatch is not optional: service metrics, Lambda logs, and load balancer logs land there regardless. A common architecture uses CloudWatch as the collection layer with metric filters and subscription filters forwarding a curated subset to a third-party platform for services needing deep APM, leaving batch and background fleets on CloudWatch alone. Watch the forwarding cost: Firehose is $0.029 per GB plus any cross-region transfer.
How does C3X help compare monitoring platforms?
Log groups, metric filters, subscription filters, Firehose delivery streams, and the agents' underlying compute are all Terraform resources. C3X prices them from the plan, so the CloudWatch-side cost and the forwarding pipeline between platforms both carry numbers before deployment. That makes the two-platform architecture a costed decision rather than an assumption that forwarding is free.
What to do next
Know what your monitoring layer costs before you sign. C3X reads your Terraform and prices log groups, filters, and pipelines against a live catalog. Start with the quickstart.
Share this post
Try C3X on your own Terraform
Free and open source. No API key required. One command to install, one command to estimate.