Skip to content
Notifications
Clear all

Anyone else's CloudGuard costs balloon after enabling all the 'recommended' rules?

3 Posts
3 Users
0 Reactions
2 Views
(@brian7)
Estimable Member
Joined: 1 week ago
Posts: 97
Topic starter   [#3178]

Just started using CloudGuard for our AWS setup a few months ago. The onboarding wizard suggested enabling a whole set of "recommended" security rules for Network Security Groups.

We turned them on, figuring it was best practice. Now our monthly bill is easily 2.5x what we initially projected. The main cost seems to be coming from the "Security Group Event Analysis" feature.

Has anyone else run into this? Is there a specific rule or set of rules that are known to be particularly expensive? I'm trying to figure out which ones we can safely dial back without losing essential coverage.



   
Quote
(@martech_tester_2)
Trusted Member
Joined: 2 months ago
Posts: 35
 

Oh yeah, that happened to us too, it's a real gotcha. The "Security Group Event Analysis" is a huge resource hog because it's scanning log events in real-time across all your groups. For us, the cost wasn't from any single rule, but from having that analysis active on *all* the recommended NSGs at once.

You don't have to turn it off completely. Try this - go into the CloudGuard rules list and filter by "Event Analysis" as the action. Disable that analysis for any rule that's tagged as "Best Practice" but not "Critical." We kept it on for things like detecting public S3 buckets or security group changes, but turned it off for the more general port-scanning alerts. Our bill dropped by about 60% and we still feel covered.

Also, check if you have it analyzing all regions. If you're only operating in two, but it's monitoring seven, you're paying for a lot of empty scanning. Good luck


Test everything, trust nothing


   
ReplyQuote
(@crmsurfer_42)
Estimable Member
Joined: 2 months ago
Posts: 67
 

We hit the same issue. The per-region point user148 mentioned was key for us - we were analyzing development regions with very low traffic, which added a ton of cost for almost no benefit.

What does your "critical" vs "best practice" breakdown look like in the rules list?


Trying to figure it out.


   
ReplyQuote