observabilityloggingcost-optimizationfinops

Log ingestion vs retention pricing: which half of the bill is bigger

Every logging platform charges twice: once to accept the data and again to keep it. On most bills the ingestion half dominates by 10x or more, which changes where you should spend optimization effort. Here is the arithmetic.

The C3X Team··7 min read

Quick answer

Log platforms bill ingestion and retention as separate meters, and ingestion is almost always the larger one. CloudWatch Logs charges $0.50 per GB ingested versus $0.03 per GB-month stored, so one month of retention costs 6% of what it cost to accept the data. Azure Monitor charges roughly $2.76 per GB ingested versus $0.12 per GB-month retained beyond the included 31 days. The practical consequence: cutting retention from 90 days to 30 days on 100 GB/day saves far less than dropping 20% of log volume at the source. Attack ingestion first, then tier what survives.

Logging bills have two meters and most teams optimize the wrong one. When the invoice spikes, the instinct is to shorten retention, because retention is a single number in a settings panel and nobody has to change application code. But on nearly every platform, the price of accepting a gigabyte is an order of magnitude higher than the price of keeping that gigabyte for a month. Shortening retention is the cheap lever that moves the small number.

The two meters, priced

PlatformIngestionRetention
CloudWatch Logs Standard$0.50 / GB$0.03 / GB-month
CloudWatch Logs Infrequent Access$0.25 / GB$0.03 / GB-month
Azure Monitor analytics logs~$2.76 / GB$0.12 / GB-month after 31 days
Azure Monitor archive tiern/a$0.02 / GB-month
Google Cloud Logging$0.50 / GiB$0.01 / GiB-month after 30 days
S3 Standard (self-managed)put request fees only$0.023 / GB-month

Read the CloudWatch row carefully. Ingestion is 16.7 times the monthly retention price. A gigabyte would have to sit in the log group for sixteen and a half months before storage caught up with what you paid to put it there. The same shape holds on Google Cloud, where $0.50 per GiB ingested dwarfs $0.01 per GiB-month of extended retention. Azure is the outlier in absolute terms because its ingestion price is high, but the ratio is still 23 to 1.

A worked example at 100 GB per day

Take a mid-sized platform pushing 100 GB of logs per day into CloudWatch Logs, roughly 3,000 GB per month. Ingestion costs 3,000 times $0.50, or $1,500 per month, every month, forever. Now consider retention. With a 30-day policy the steady-state stored volume is about 3,000 GB, costing 3,000 times $0.03, or $90 per month. Extend retention to 90 days and stored volume settles near 9,000 GB, costing $270 per month.

So tripling retention from 30 to 90 days adds $180 per month against a $1,500 ingestion charge. Conversely, cutting retention from 90 back to 30 saves $180, about 10% of the total. Meanwhile, dropping 20% of log volume at the source saves $300 in ingestion plus $18 in storage, and it does so without destroying the historical record anybody actually needed during the last incident.

Why the pricing is shaped this way

Ingestion is where the expensive work happens. Accepting a log line means parsing it, extracting fields, building inverted indexes, updating live tail streams, evaluating metric filters and alert rules, and replicating the result. Storage afterwards is a commodity: compressed bytes on cheap disks. Vendors price the meters to match their cost structure, which means the pricing model is telling you something true. Every byte you send costs real compute to process, and that is the byte worth not sending. This is the same principle behind broader observability cost optimization.

The tiers that break the rule

Both AWS and Azure now sell reduced-capability ingestion tiers that lower the expensive meter in exchange for weaker query features. CloudWatch Logs Infrequent Access halves ingestion to $0.25 per GB but drops support for metric filters, subscription filters, and live tail. Azure Basic Logs cost roughly $0.65 per GB against $2.76 for analytics logs, and its auxiliary tier drops to about $0.15 per GB, with search-job style access instead of full interactive query.

These tiers are the single highest-leverage change available to most teams, because they move the meter that dominates the bill. If 70% of your 100 GB/day is verbose application debug output that nobody alerts on, routing that 70 GB/day to Infrequent Access takes its ingestion from $1,050 to $525 per month. No code changes, no lost data, just a different destination log group.

Retention still matters, for two reasons

The first is compliance. If a regulator requires seven years of access logs, retention is not an optimization target at all, it is a requirement, and the right question is which tier holds it. Seven years of 3,000 GB/month in CloudWatch at $0.03 per GB-month means 252,000 GB stored by year seven, or $7,560 per month at the end. Exporting to S3 Glacier Deep Archive at $0.00099 per GB-month puts that same volume at $250 per month, a 30x reduction on the storage half.

The second is query cost, which is a third meter people forget. CloudWatch Logs Insights charges $0.005 per GB scanned. A dashboard query that sweeps 90 days of a 3,000 GB/month log group scans 9,000 GB and costs $45 per execution. Run it on a 5-minute refresh and you have invented a $388,800 per month dashboard. Shorter retention caps the worst case here, which is a real argument for it that has nothing to do with storage prices. See retention strategy for the policy side.

The order of operations

Work the meters in descending order of price. First, cut volume at the source: sampling, log level discipline, and dropping the health check lines that make up a surprising share of most access logs. Second, route what remains to the cheapest ingestion tier that still supports how you query it. Third, set retention from the compliance requirement rather than from habit, and export anything longer than 30 days to object storage. Fourth, audit scheduled queries and dashboards for scan volume.

Log groups, retention settings, and subscription filters are all Terraform resources, which means the decision that sets your ingestion bill is a code review decision. Price the logging estate from the plan against the resource catalog so a new log group with default retention and Standard ingestion gets priced before it starts billing.

FAQ

Is log ingestion or log retention more expensive?

Ingestion, by a wide margin. CloudWatch Logs charges $0.50 per GB ingested versus $0.03 per GB-month stored, a 16.7x ratio, so a gigabyte would need to sit in storage for over sixteen months before retention cost matched ingestion cost. Google Cloud Logging is $0.50 per GiB ingested versus $0.01 per GiB-month of extended retention. Azure is roughly $2.76 per GB ingested versus $0.12 per GB-month. On every major platform, ingestion dominates the bill.

How much does shortening log retention actually save?

Less than most teams expect. At 100 GB/day into CloudWatch Logs, ingestion costs $1,500 per month. Retaining 90 days holds about 9,000 GB at $270 per month; cutting to 30 days holds 3,000 GB at $90 per month. The saving is $180 per month, about 10% of the total bill, and it costs you two months of incident history. Cutting 20% of log volume at the source saves $318 per month and keeps the history intact.

What are cheap log ingestion tiers and what do they give up?

CloudWatch Logs Infrequent Access halves ingestion to $0.25 per GB but drops metric filters, subscription filters, and live tail. Azure Basic Logs cost roughly $0.65 per GB versus $2.76 for analytics logs, and the auxiliary tier is about $0.15 per GB, both with search-job access instead of full interactive query. These tiers suit verbose application output that nobody alerts on, which is often the majority of log volume.

How do log query charges fit into the cost model?

They are a third meter. CloudWatch Logs Insights charges $0.005 per GB scanned. A query sweeping 90 days of a log group that ingests 3,000 GB per month scans 9,000 GB and costs $45 per run, so a dashboard refreshing every five minutes would cost hundreds of thousands per month. Shorter retention caps this worst case, which is a legitimate reason to limit retention independent of storage prices.

What is the cheapest way to hold logs for compliance?

Export to object storage rather than paying platform retention. Seven years of 3,000 GB per month accumulates 252,000 GB, which costs about $7,560 per month at CloudWatch's $0.03 per GB-month by year seven. The same volume in S3 Glacier Deep Archive at $0.00099 per GB-month costs roughly $250 per month, a 30x reduction, with retrieval latency measured in hours, which is acceptable for records nobody queries interactively.

How does C3X help with logging cost?

Log groups, retention policies, subscription filters, and export destinations are Terraform resources, so the configuration that sets your ingestion bill is created in a pull request. C3X prices that infrastructure from the plan, which surfaces a new log group defaulting to Standard ingestion and never-expire retention before it starts billing, rather than after a quarter of accumulated charges shows up on the invoice.

What to do next

Price your logging estate before it starts billing. C3X reads your Terraform and prices log groups, retention, and exports against a live catalog. Start with the quickstart.

Try C3X on your own Terraform

Free and open source. No API key required. One command to install, one command to estimate.