Skip to content

Flat-Cost Flow-Log Analysis

VPC Flow Logs are the runaway-cost risk in any SIEM. AI SIEM keeps them in S3 and runs scheduled Athena sweeps for the patterns that matter — port scanning and large data egress — so cost scales with query cadence, not traffic volume or account count. Every flow is retained in S3 and queryable on demand; a traffic spike cannot trigger a surprise bill.

The cost model

Flow-log cost splits into two parts that behave very differently:

  • Delivery to S3 is cheap — roughly $0.25/GB plus S3 storage, billed by AWS. Even a busy VPC logging ALL traffic at tens of GB/day is a modest, storage-class-manageable line.
  • Processing every record is where cost runs away — scoring each flow object in a Lambda is what can reach hundreds of dollars a day. This is the part AI SIEM bounds.

Because delivery is cheap, the default traffic type is ALL — the full picture always lands in the datalake. The cost control is on the analysis side, not by discarding data at capture.

Three detection paths

Path What it detects Cost shape
Scheduled scan sweep (Athena) Port scanning — a source hitting many distinct REJECT ports Fixed: one partition-pruned query every 15 min
Scheduled exfil sweep (Athena) Large-egress / data exfiltration — src→dst pairs over the byte threshold Fixed: one partition-pruned query per hour
On-demand flow query (Athena) Data exfiltration / destination detail around an AI Monitor anomaly Per incident: cents, pruned to one resource + hour

Flow logs are queried in place by Athena — never scored per-object. Detection latency is a short sweep interval (roughly 15 minutes for port-scan, hourly for exfiltration) rather than seconds. The built-in VPC Flow panel shows the estimated scan cost, so there are no surprises. CloudTrail, GuardDuty, and Config ingestion are on a separate, always-on path and are never affected by flow-log analysis. Choose the flow mode (Athena or off) under Configure → VPC Flow.

Cold-storage tiering for long retention

For long-retention deployments (a large DatalakeRetentionDays, e.g. 2555 for a 7-year mandate) or very high flow-log volume, set the EnableColdStorageTiering stack parameter to true. It turns on S3 Intelligent-Tiering for the datalake and flow-log buckets, moving rarely-read data to cheaper tiers (about 30% less after 30 days, up to ~80% on multi-year tails). It uses only instantly-readable tiers, so Athena queries keep working with no restore and no retrieval fee. Leave it off for short retention. The WORM audit store is never tiered.

Do not monitor the SIEM's own VPC

The Log Processor VPC exists because OpenSearch requires it, not because it carries workload traffic worth monitoring. create-flowlogs refuses to target the shared infrastructure VPC — monitoring the VPC the SIEM runs in creates an amplification loop where its own API calls generate flow records.