Synthetic monitoring and alerting cost: what every canary and alarm adds up to
Canaries and alarms are individually cheap enough that nobody budgets for them, which is exactly how a few thousand dollars a month appears with no owner. Here is the per-unit math and how it compounds.
Quick answer
CloudWatch Synthetics charges $0.0012 per canary run, so a canary at 1-minute frequency runs 43,200 times per month and costs $51.84; the same canary at 5 minutes costs $10.37. Standard alarms are $0.10 per month, high-resolution alarms $0.30, composite alarms $0.50. Azure availability tests are roughly $0.0012 per execution with similar arithmetic. The compounding factor is multiplication: 10 endpoints times 5 global regions times 1-minute frequency is 50 canaries and $2,592 per month, before the Lambda execution and log storage each run generates.
Nobody approves a $2,500 per month synthetic monitoring bill. It arrives as fifty individually reasonable decisions, each costing about fifty dollars, made by different teams over eighteen months. Canaries and alarms are the classic small-unit-price, high-multiplicity cost, and the only defense is knowing the per-unit arithmetic before the multiplication happens.
The unit prices
| Item | Price | Monthly at max frequency |
|---|---|---|
| CloudWatch Synthetics canary run | $0.0012 | $51.84 at 1 min |
| Standard CloudWatch alarm | $0.10 / month | $0.10 |
| High-resolution alarm | $0.30 / month | $0.30 |
| Composite alarm | $0.50 / month | $0.50 |
| Anomaly detection alarm | $0.30 / month per metric | $0.30 |
| SNS notification (email) | $2.00 per 100,000 | negligible |
| SNS notification (SMS, US) | ~$0.00645 each | see below |
Read the canary row first, because it is the one that scales badly. $0.0012 sounds like nothing. A canary running every minute executes 1,440 times a day, 43,200 times a month, for $51.84. Drop to every 5 minutes and it is 8,640 runs for $10.37. The frequency choice is a 5x cost decision made in a dropdown.
The multiplication problem
Synthetic monitoring multiplies along three axes: endpoints, geographies, and frequency. A team monitoring 10 critical user journeys from 5 regions at 1-minute frequency operates 50 canaries at $51.84 each, which is $2,592 per month. The same coverage at 5-minute frequency from 3 regions is 30 canaries at $10.37, or $311 per month, an 88% reduction.
Ask what the extra frequency buys. A 1-minute canary detects an outage on average 30 seconds after it starts; a 5-minute canary averages 2.5 minutes. If your incident response time from page to acknowledgment is 8 minutes, the 2 minutes of extra detection latency is noise against the total, and you paid $2,281 per month for it. The exception is genuinely revenue-critical checkout flows where two minutes of downtime is measurable money, and those deserve 1-minute canaries. Most endpoints do not.
The costs that hide behind a canary
A CloudWatch Synthetics canary is a Lambda function, and it bills like one in addition to the per-run charge. A heavyweight browser canary using the Puppeteer runtime at 2,048 MB of memory running for 12 seconds consumes 24 GB-seconds per run. At $0.0000166667 per GB-second that is $0.0004 per run, or $17.28 per month at 1-minute frequency, a 33% surcharge on the $51.84 nobody counts.
Then the artifacts. Each run writes logs to CloudWatch Logs and screenshots plus HAR files to S3. A browser canary producing 400 KB of artifacts per run generates 17.3 GB per month at 1-minute frequency. In S3 Standard that is $0.40 per month, trivial, but the CloudWatch Logs side at $0.50 per GB for maybe 1 GB per month is another $0.50, and across 50 canaries these add roughly $45 per month plus a steadily growing S3 bucket that nobody lifecycles. Set an S3 lifecycle rule to expire canary artifacts after 14 days and the problem stays bounded.
Alarms: cheap individually, structurally expensive
Alarms cost $0.10 per month each, which means 2,000 alarms cost $200. That is not the problem. The problem is what alarms cost when they fire. An SNS topic paging via SMS at roughly $0.00645 per US message is nothing for one alert, but a flapping alarm sending 500 messages during a bad hour across a 40-person on-call rotation is 20,000 messages and $129 for a single incident. Third-party paging platforms billing $19 to $41 per responder per month add another layer, and that one is priced per human rather than per alert.
Anomaly detection alarms are worth calling out because they cost $0.30 per metric rather than $0.10, and the model training runs continuously. Applying anomaly detection broadly across a few hundred metrics turns a $30 line into a $90 line, still small, but the pattern of "enable it everywhere because it seems smart" is how these compound. See alarm pricing detail for the tier breakdown.
A sane configuration
| Endpoint class | Frequency | Regions | Cost each |
|---|---|---|---|
| Revenue-critical checkout | 1 min | 3 | $155.52 |
| Core API health | 5 min | 3 | $31.11 |
| Secondary user journeys | 15 min | 2 | $6.91 |
| Internal tools | 30 min | 1 | $1.73 |
Tiering by business impact rather than monitoring everything at the highest frequency is the entire optimization. Two checkout canaries, six core API canaries, twenty secondary journeys, and fifteen internal tools under this scheme costs $311 + $187 + $138 + $26, about $662 per month, versus $3,300 if everything ran at 1 minute from 5 regions.
Keeping it from drifting
Canaries and alarms are Terraform resources, which is good news: they are created in pull requests where someone can see the frequency and region count before the multiplication happens. Require a business justification for any 1-minute canary, default new canaries to 5 minutes, cap region count at 3 unless there is a regional availability requirement, and audit for canaries pointing at endpoints that no longer exist. Price the monitoring resources from the plan against the resource catalog so a pull request adding fifteen canaries shows the $780 per month it implies rather than looking like a routine config change.
FAQ
How much does a CloudWatch Synthetics canary cost?
$0.0012 per run. At 1-minute frequency a canary runs 43,200 times per month, costing $51.84. At 5 minutes it runs 8,640 times for $10.37, and at 15 minutes 2,880 times for $3.46. On top of the per-run charge you pay Lambda execution, typically about $17 per month for a browser canary at 1-minute frequency, plus CloudWatch Logs and S3 charges for screenshots and HAR artifacts.
Why do synthetic monitoring bills grow so fast?
They multiply along three axes: endpoints, regions, and frequency. Ten user journeys checked from five regions every minute is 50 canaries at $51.84 each, or $2,592 per month. The same coverage at 5-minute frequency from three regions is 30 canaries at $10.37, or $311 per month, an 88% reduction. Each individual decision looks like a $50 line item, which is why nobody blocks it.
Is 1-minute canary frequency worth the cost?
Usually not. A 1-minute canary detects an outage on average 30 seconds in, a 5-minute canary 2.5 minutes in. If your time from page to acknowledgment is 8 minutes, the 2 minutes of extra detection latency is noise against total incident duration, and you paid roughly five times more for it. Reserve 1-minute frequency for revenue-critical flows where two minutes of downtime is measurable money.
What do CloudWatch alarms cost?
$0.10 per standard alarm per month, $0.30 for high-resolution alarms, $0.50 for composite alarms, and $0.30 per metric for anomaly detection alarms. Two thousand standard alarms cost $200 per month, which is rarely the issue. The larger cost is notification: SMS paging at roughly $0.00645 per US message means a flapping alarm sending 500 messages to a 40-person rotation costs $129 in one incident.
What hidden costs come with synthetic canaries?
Lambda execution, logs, and artifacts. A browser canary at 2,048 MB running 12 seconds uses 24 GB-seconds per run, about $17.28 per month at 1-minute frequency, a 33% surcharge on the per-run price. Each run also writes CloudWatch Logs and 400 KB or so of screenshots and HAR files to S3, roughly 17.3 GB per month per canary. Set an S3 lifecycle rule expiring artifacts after 14 days.
How does C3X help control monitoring resource cost?
Canaries, alarms, SNS topics, and their supporting Lambda and S3 resources are all defined in Terraform, so they are created in pull requests. C3X prices them from the plan, which means a change adding fifteen canaries at 1-minute frequency shows its roughly $780 per month implication in review, rather than looking like a routine configuration edit that nobody costs.
What to do next
See what a canary config change costs before it merges. C3X reads your Terraform and prices monitoring resources against a live catalog. Start with the quickstart.
Share this post
Try C3X on your own Terraform
Free and open source. No API key required. One command to install, one command to estimate.