Asterrr's Handbook

Cost visibility

Tagging, cost categories, Cost Explorer, Budgets, Data Exports, anomaly detection and rightsizing tools for seeing and controlling spend across an organization.

Exam tasks: 1.5 (determine cost optimization and visibility strategies), 3.5 (identify opportunities for cost optimization)

The decision: who spent what, is it within budget, and what should happen automatically when it isn't? Pick the tool that answers the question at the granularity asked, with the least custom work.

Which tool answers which question

ToolAnswersGranularityActs on its own?
Cost ExplorerSpend and usage trends, forecasts, RI and Savings Plans coverageMonthly and daily; hourly opt-in for recent daysNo
Data Exports / CUREvery line item with tags, cost categories and discountsHourly, resource-levelNo, you query it
AWS BudgetsActual or forecast spend against a thresholdUpdated several times a dayYes, with budget actions
Cost Anomaly DetectionUnexpected spikes, with a likely root causeDaily ML evaluationAlerts only
Compute OptimizerRight size for compute resourcesPer resourceNo
S3 Storage LensStorage growth, cold data, missing lifecycle rulesOrg, account, bucket, prefixNo
Trusted AdvisorIdle resources, low RI use, security and limits checksPer checkNo

Tagging for cost allocation

  • User-defined tags are the keys you apply, such as CostCenter or Product. In reports they appear with a user: prefix.
  • AWS-generated tags are applied by AWS, such as aws:createdBy or the CloudFormation stack name tag.
  • Neither appears in billing data until it's activated in the Billing console, and only the management account (the payer) can activate tags for the organization. Activated tags can take up to 24 hours to show up.
  • Tags apply to usage from activation onward. You can request a backfill of up to 12 months to apply current activations to history.
  • Accounts are the cleanest cost boundary. A one-account-per-workload strategy often answers "who spent it" better than tags alone.

Tagged but invisible

A team tags every resource with Project, but Cost Explorer shows nothing when grouped by that tag. The tag was never activated as a cost allocation tag. Tagging resources isn't enough on its own.

Keeping tags consistent

NeedMechanism
Standard key spelling and allowed values (CostCenter, not costcenter)Tag policy in Organizations
Require a tag when a resource is createdSCP denying the create action when aws:RequestTag/CostCenter is null
Tag everything a product createsService Catalog TagOptions, CloudFormation stack tags
Find untagged resourcesTag Editor, the AWS Config required-tags rule

See multi-account governance for tag policy behaviour.

Cost Categories

Rules that map costs into business groupings, such as "Platform", "Checkout team" or "Shared", using accounts, tags, services, charge types or other categories.

  • Fix messy data without retagging: CostCenter values cc-104, CC104 and account 2222... can all map to "Checkout".
  • Split charges spread a shared cost, such as a central networking account, across other categories evenly, proportionally or by fixed percentages.
  • Categories appear in Cost Explorer, Budgets, Anomaly Detection and Data Exports.

Consolidated billing and discount sharing

  • One bill for the organization. Usage from all accounts is combined for volume pricing tiers, such as S3 and data transfer tiers.
  • Reserved Instances and Savings Plans are shared across accounts by default. A commitment first covers the account that bought it, then applies to matching usage elsewhere.
  • The management account can turn off discount sharing for specific accounts, for example a subsidiary that must be billed at its own rates.
  • AWS Billing Conductor produces pro forma bills with custom rates for chargeback or reselling, without changing the real bill.

See pricing models for choosing between RIs, Savings Plans and Spot.

Cost Explorer

  • Group and filter by service, account, Region, tag, cost category, usage type and more.
  • History of 13 months by default, and a forecast up to 12 months ahead.
  • Reports for RI and Savings Plans utilization (are we using what we bought?) and coverage (how much eligible usage is covered?), plus purchase recommendations.
  • Rightsizing recommendations for EC2, powered by the same engine as Compute Optimizer.

AWS Budgets

  • Budget types: cost, usage, RI utilization and coverage, Savings Plans utilization and coverage.
  • Alert on actual or forecasted amounts, by email, SNS or chat channels.
  • Filter by account, tag or cost category, so each team can have its own budget.
  • Budget actions run when a threshold is crossed, automatically or after approval:
    • apply an IAM policy to a user, group or role (for example, deny ec2:RunInstances),
    • apply an SCP to an account or OU,
    • stop specific EC2 or RDS instances.

Exam signal

"Notify when spend is forecast to exceed" is Budgets with a forecasted alert. "Automatically stop developers from launching more resources when the sandbox budget is exhausted" is a budget action applying an SCP or IAM policy. A custom Lambda function on a CloudWatch billing alarm is more work.

Data Exports and the Cost and Usage Report

  • Data Exports delivers billing data to S3 on a schedule, in CSV or Parquet. Export types include CUR 2.0, FOCUS (the open FinOps schema) and cost optimization recommendations.
  • CUR data is the most detailed: hourly, per resource ID, with tags, cost categories, RI and Savings Plans amortization.
  • Query it with Athena (a Glue table over the S3 prefix) and build dashboards with QuickSight, for example the Cloud Intelligence Dashboards.
  • Deliver it to the management account or a dedicated FinOps account and share it from there.

Legacy: use Data Exports (CUR 2.0) instead

The original Cost and Usage Report (now called legacy CUR) still works, but new reports should use Data Exports, which has a fixed schema and supports column selection.

Cost Explorer for per-resource chargeback

Cost Explorer shows resource-level data only for a short recent window and only for some services. For hourly, resource-level chargeback over months, or joins with your own data, use CUR 2.0 with Athena.

Cost Anomaly Detection

  • Machine learning monitors watch AWS services, linked accounts, cost categories or cost allocation tags.
  • Alert subscriptions set a threshold (absolute or percentage impact) and a frequency: individual alerts through SNS, or daily or weekly email summaries.
  • Each anomaly shows a likely root cause: the service, account, Region and usage type behind it.

Use it when the question says "unexpected", "unusual" or "detect a spike without setting fixed thresholds".

Recommendation tools

14 days
Compute Optimizer's default lookback. Enhanced infrastructure metrics extend it to about 3 months.
12 months
Maximum backfill for cost allocation tag activation.
15 months
Metric history with S3 Storage Lens advanced metrics. Free metrics keep 14 days.
24 hours
Time for newly activated cost allocation tags to appear.
  • Compute Optimizer: opt in at the organization level from the management account or a delegated admin. Covers EC2, Auto Scaling groups, EBS, Lambda, ECS services on Fargate, RDS and Aurora, and flags idle resources. Memory recommendations need the CloudWatch agent to publish memory metrics.
  • S3 Storage Lens: organization-wide dashboards of object counts, bytes, request activity and data-protection settings. Advanced metrics add prefix-level detail, activity metrics and recommendations. Export metrics to S3 or publish to CloudWatch.
  • Trusted Advisor: checks for idle load balancers, unassociated Elastic IPs, low-utilization instances and RI expirations, plus security, fault tolerance and service quota checks. The full set of checks and the organization view need a Business, Enterprise On-Ramp or Enterprise support plan.

Acting on these findings is covered in cost optimization and performance and rightsizing.

Scenarios

Scenario
Harbor Analytics runs 45 accounts in AWS Organizations. Finance wants a monthly report of cost per product line. Product lines are identified by a Product tag, but teams have used values such as 'search', 'Search' and 'srch', and two product lines share one account whose cost must be split 70/30. Which approach requires the LEAST effort?
Scenario · choose 2
A company gives each developer a sandbox account in a Sandbox OU. When a sandbox account's monthly spend reaches its limit, the company wants to automatically prevent new EC2 instances from being launched in that account and notify the developer, without writing custom code. Which TWO actions should the architect take?
Scenario
A FinOps team needs to join hourly, resource-level AWS cost data from all member accounts with an internal table of application owners, and run ad hoc SQL over the past 18 months. What should the team use?

Further reading

On this page