Guides · Billing
A surprise AWS bill usually comes down to a few things: resources that kept running after anyone needed them, charges for things that are stopped or detached, and per-GB charges nobody expected. Cost Explorer shows which service and which usage type the money went to. Each cause below lists what to look for there, and links to a guide with the fix.
BoxUsage:t2.micro is running hours of t2.micro instances. The usage type usually tells you what kind of resource is costing money. In us-east-1 most usage types have no prefix; in other regions they start with a region code.With the CLI (each Cost Explorer API request costs $0.01):
aws ce get-cost-and-usage --time-period Start=2026-07-01,End=2026-10-01 \
--granularity MONTHLY --metrics UnblendedCost \
--group-by Type=DIMENSION,Key=SERVICE
aws ce get-cost-and-usage --time-period Start=2026-09-01,End=2026-10-01 \
--granularity MONTHLY --metrics UnblendedCost UsageQuantity \
--group-by Type=DIMENSION,Key=USAGE_TYPE
Cost Explorer data can lag by up to 24 hours, so very recent usage may not show yet.
The free checkup looks for every cause in this table.
| Cause | Usage types to look for | Guide |
|---|---|---|
| Idle, oversized or older EC2 instances | BoxUsage: followed by the instance type | Idle and oversized EC2 |
| Stopped instances still paying for their disks | EBS:VolumeUsage | Stopped EC2 and RDS |
| Unattached EBS volumes and old snapshots | EBS:VolumeUsage, EBS:SnapshotUsage | Unattached volumes and snapshots |
| Volumes still on gp2 | EBS:VolumeUsage.gp2 | gp2 to gp3 |
| NAT gateway hours and data processing | NatGateway-Hours, NatGateway-Bytes | NAT gateway cost |
| Idle Elastic IPs | PublicIPv4:IdleAddress | Public IPv4 charge |
| Load balancers with nothing behind them | LoadBalancerUsage, LCUUsage | Idle load balancers |
| Idle, oversized or Multi-AZ development databases | InstanceUsage:db., Multi-AZUsage:db. | Reduce RDS cost |
| CloudWatch log groups that never expire | TimedStorage-ByteHrs, DataProcessing-Bytes | CloudWatch Logs cost |
The checkup also looks for three things without a guide yet:
The checkup mentions these as observations, without a savings estimate:
DataTransfer-Out-Bytes. The checkup notes it when it cost more than $50 last month.General advice the checkup doesn't cover: to catch the next spike sooner, turn on AWS Cost Anomaly Detection. It uses machine learning models on your Cost Explorer data, runs about three times a day, and alerts you by email or through an Amazon SNS topic. Because Cost Explorer lags, it can take up to 24 hours to detect an anomaly.
The free checkup looks for all of these automatically. A read-only script collects Cost Explorer data, resource settings and 14 days of utilization metrics. By default it scans every region with more than $0.50 of spend last month, plus us-east-1. The analysis runs in your browser and lists each finding with its estimated monthly saving.
BoxUsage example), Detecting unusual spend with AWS Cost Anomaly Detection (AWS documentation)Lambda-GB-Second $0.0000166667 and Lambda-GB-Second-ARM $0.0000133334 per GB-second, first pricing tier.DataTransfer-Out-Bytes $0.09/GB for the first 10 TB a month; 100 GB a month free, aggregated globally.Prices are AWS on-demand list prices for US East (N. Virginia), checked October 3, 2026. Other regions differ.