AmazonVPC

other

ClientVPN-EndpointHours

The Client VPN feature enables remote access to AWS and on-premises networks. Charges are per Client VPN endpoint hour for active client connections.

PublicIPv4:InUseAddress

An in-use Public IPv4 Address is an address currently attached to a running resource such as an EC2 instance, a NAT Gateway, or an Elastic Load Balancer. AWS services such as these often require Public IPv4 Addresses to enable internet connectivity. Charges for in use Public IPv4 Addresses are hourly and are billed in one-second increments, with a minimum of 60 seconds billed.

PublicIPv4:IdleAddress

An idle Public IPv4 Address is an address not currently associated with any running resource. You are charged the same amount for a Public IPv4 Address whether it is in use or idle. Charges for idle Public IPv4 Addresses are hourly and are billed in one-second increments, with a minimum of 60 seconds billed.

TransitGateway-Hours

The number of attachment hours for AWS Transit Gateways. Connections are used to route traffic between your VPCs, on-premises networks, and AWS services. These connections include attachments such as VPCs, Direct Connect Gateways, and VPNs.

TransitGateway-Bytes

The amount of data (per GB) processed by AWS Transit Gateway. This includes data transferred between connected VPCs, on-premises networks, and other AWS services routed through the Transit Gateway.

ClientVPN-ConnectionHours

The Client VPN feature enables remote access to AWS and on-premises networks. Charges are per Client VPN connection hour for the number of subnets associated with the Client VPN.

VPCLattice-Service-Hourly

The number of hours VPC Lattice services are running.

VPCLattice-DataProcessing-Bytes

The amount of data (per GB) processed by the VPC Lattice service, including the data each service receives and the response each service sends. Inter-AZ data processing is not charged.

VPCLattice-RequestCount-Free

The number of free HTTP requests or TCP connections. You are provided 300,000 requests/connections per hour at no additional cost.

IPAddressManager-IP-Hours

The number of hours per active IP address managed by the IP Address Manager (IPAM) in the IPAM Advanced Tier. This tier provides enhanced address management features, such as private IPv4 management and IP address history auditing.

VerifiedAccess-DataProcess-Bytes

The amount of data processed (per GB) by HTTP(S) Verified Access endpoints. Verified Access enables secure connectivity to endpoints of HTTP(S) and non-HTTP(S) applications. HTTP(S) applications include resources such as web servers and APIs.

VerifiedAccess-App-Hours

The number of hours per application associated with active HTTP(S) Verified Access endpoints, billed in hourly increments. Pricing is tiered, with reduced rates once usage exceeds 148,800 hours. Verified Access enables secure connectivity to endpoints of HTTP(S) and non-HTTP(S) applications. HTTP(S) applications include resources such as web servers and APIs.

ENI-Mirror

The Traffic Mirroring feature of Amazon EC2 Instance elastic network interfaces (ENIs) replicates network traffic from an ENI to a target for monitoring purposes. Charges are hourly per ENI that is configured for Traffic Mirroring.

Analysis-Runs

The number of analysis processed by VPC Reachability Analyzer. Reachability Analyzer analyzes the network path between VPC source and destination resources to determine the connectivity status.

TGW-Multicast-Consumer-Bytes

Multicast is a feature of AWS Transit Gateway that delivers network traffic from one source to multiple destinations. It is priced per GB of data processed for each multicast receiver instance.

NetworkInterface-Assessment

The number of elastic network interfaces (ENIs) analyzed from a Network Access Analyzer network assessment. The Network Access Analyzer identifies AWS resources that may have unintended or misconfigured network access.

PublicIPv4:ContiguousBlock

The number of hours each public IPv4 address in an Amazon-provided contiguous IPv4 block i running. Contiguous blocks consist of sequential IP addresses grouped together to simplify management and allocation.

VpcLattice-Service-Network-Resource-Hours

The number of hours a VPC Lattice service network is running. A service network defines a structured grouping of services and associated resource configurations.

VpcResource-Provider-Bytes

The amount of data (per GB) processed by a VPC resource provider. Charges apply to the data transferred from the provider's resources to consumer resources across accounts or regions.

VerifiedAccess-non-HTTP-App-Hours

The number of hours per application associated with active non-HTTP(S) Verified Access endpoints, billed in hourly increments. Verified Access enables secure connectivity to endpoints of HTTP(S) and non-HTTP(S) applications. HTTP(S) applications include resources such as load balancers and RDS instances.

vpcendpoint

VpcEndpoint-Hours

The number of hours a VPC Interface Endpoint is provisioned, regardless of traffic or usage, billed in hourly increments.

VpcEndpoint-Bytes

The amount of data (per GB) processed by Interface Endpoints. Pricing is tiered, with reduced rates applied after processing the first petabyte (PB) and the next 4 PB.

VpcEndpoint-GWLBE-Hours

The number of hours a Gateway Load Balancer Endpoint is provisioned, regardless of traffic or usage, billed in hourly increments.

VpcEndpoint-GWLBE-Bytes

The amount of data (per GB) processed by Gateway Load Balancer Endpoints.

VpcResource-Consumer-Bytes

The amount of data (per GB) processed by a VPC resource consumer. Charges apply to the data received by consumer resources from provider resources across accounts or regions.

data-transfer

DataTransfer-Regional-Bytes

The amount of data (in bytes) transferred within the same Availability Zone.

DataTransfer-Out-Bytes

The amount of data (in bytes) transferred out of AWS to the internet.

DataTransfer-In-Bytes

The amount of data (in bytes) transferred into AWS from the internet. Data transferred into AWS does not incur a fee.

AWS-Out-Bytes

The amount of data (in bytes) transferred out of AWS. If there are two regions in the prefix, the first represents the source region, and the second represents the destination region. If there is only one region in the prefix, the prefix represents the AWS source region.

AWS-In-Bytes

The amount of data (in bytes) transferred into AWS. Data transferred into AWS does not incur a fee. If there are two regions in the prefix, the first represents the source region, and the second represents the destination region. If there is only one region in the prefix, the prefix represents the AWS source region.

DataTransfer-xAZ-Out-Bytes

The amount of data (in bytes) transferred out of an AWS Availability Zone to another Availability Zone within the same region.

DataTransfer-xAZ-In-Bytes

The amount of data (in bytes) transferred into an AWS Availability Zone from another Availability Zone within the same region. Each Inter-AZ data transfer also has a line item for DataTransfer-xAZ-Out-Bytes in which the cost is applied.

CloudFront-In-Bytes

The amount of data (in bytes) transferred into an AWS region from CloudFront. Each CloudFront data transfer also has a line item for CloudFront-Out-Bytes in which the cost is applied.

CloudFront-Out-Bytes

The amount of data (in bytes) transferred out of an AWS region to CloudFront.

DataXfer-Out

The amount of AWS Direct Connect data (in bytes) transferred out over a virtual interface. If there is a postfix of `dc.3` that indicates the data was transferred over a private virtual interface. Otherwise, the data was transferred over a public virtual interface. The first region in the prefix represents the source region, and the second represents the destination region.

CloudFrontChina-In-Bytes

The amount of data (in bytes) transferred into an AWS region from CloudFront China. Each CloudFront China data transfer also has a line item for CloudFrontChina-Out-Bytes in which the cost is applied.

CloudFrontChina-Out-Bytes

The amount of data (in bytes) transferred out of an AWS region to CloudFront China.

cloud-connectivity

VPN-Usage-Hours:ipsec.1

The number of hours a Cross-Region Interface Endpoint is provisioned per remote AWS Region per service, regardless of traffic or usage, billed in hourly increments. Cross-Region Connectivity is used to connect VPC endpoints to different regions. Data transfer costs will also apply.

dt-data-transfer

DataTransfer-AZ-In-Bytes

The amount of data (in bytes) transferred in from the same Availability Zone. Data transferred within the same Availability Zone does not incur a fee.

DataTransfer-AZ-Out-Bytes

The amount of data (in bytes) transferred out to the same Availability Zone. Data transferred within the same Availability Zone does not incur a fee.