Skip to content
Notifications
Clear all

Just built a custom dashboard for our Azure spend vs. security posture - here's the config.

3 Posts
3 Users
0 Reactions
0 Views
(@cloud_cost_owen)
Reputable Member
Joined: 5 months ago
Posts: 180
Topic starter   [#29468]

Hey folks! Wanted to share a quick weekend project that's been super useful for our FinOps + SecOps sync-up meetings. We were tired of switching between Prisma Cloud alerts and the Azure Cost Management dashboard, so I built a custom view that maps our spend to our security posture (specifically compliance scores).

The core idea: visualize if our biggest spenders are also our biggest security risks. Used Prisma's APIs and Azure Cost Management exports.

Here's the main config snippet for the data pull and join:

```python
# Simplified version of our aggregator
def get_combined_data(azure_subscription_id, timeframe='MonthToDate'):
# Pull cost data from Azure export
cost_df = get_azure_cost_data(subscription_id, timeframe)
# Pull compliance data from Prisma
prisma_df = get_prisma_compliance_score(subscription_id)
# Merge on resource ID / subscription tag
merged_df = pd.merge(cost_df, prisma_df, on='resource_id', how='left')
merged_df['risk_weighted_spend'] = merged_df['cost'] * (1 - merged_df['compliance_score'])
return merged_df.sort_values('risk_weighted_spend', ascending=False)
```

Key takeaways so far:
* Found a cluster of non-compliant, expensive VMs nobody was watching 😅
* Immediate action: tagged the team, applied Terraform fixes, and are now evaluating Reserved Instances for them once they're compliant.
* The dashboard highlights "low-hanging fruit" - high spend, low compliance score resources.

Biggest win: This made the "cost of *not* fixing" a security issue very clear to both teams. The visualization is simple: a scatter plot with cost on one axis and compliance score on the other.

Anyone else done something similar? Would love to compare approaches!

#savings



   
Quote
(@harryp)
Reputable Member
Joined: 2 months ago
Posts: 279
 

Hi there, nice work on the dashboard. I'm a community manager for a mid-sized SaaS platform (around 300 employees). We handle similar FinSecOps data across AWS and GCP, and for visualization and alerting we run a combination of Datadog for the unified view and Keep for cost anomaly alerts.

Looking at what you've built versus using a dedicated platform, here are a few concrete points from our experience:

1. **Sustained Integration Effort:** Your script works great for proofs of concept. Maintaining the API integrations across vendor changes becomes a part-time job. We saw about 2-3 hours a week of devops time to keep our similar custom connectors running before we switched.

2. **Real Cost of a Platform:** A tool like Datadog for this use case starts around $23-$30 per host/month, and you'll need the Cloud Cost Management add-on. The hidden cost is the data ingestion volume; if your Azure exports are large, your bill can scale unpredictably. For a pure cost-and-compliance overlay, you might find a more niche tool like ZD-AI Cloud Spend (starts at ~$5k/year for midsize) is actually cheaper.

3. **Where Custom Builds Break:** You're joining on `resource_id`. This falls apart immediately for unassigned or orphaned spend (like unused disks) which have no security context, skewing your "risk_weighted_spend" metric. Platforms typically handle this by allowing multiple reconciliation methods and tagging strategies.

4. **Clear Win for a Platform:** Real-time alerting and historical trend analysis. Setting a threshold alert for when a resource group's cost spikes while its compliance score drops below 80% is a one-click rule in Datadog. Building and maintaining that alert logic yourself, with backtesting, is a significant lift.

I'd recommend you stick with your custom dashboard for now to refine the logic, but start evaluating platforms if your team's time is better spent elsewhere. To make a clean call, tell us your monthly Azure spend band and whether you have dedicated engineering time to maintain this as a product.


~Harry


   
ReplyQuote
(@amyc)
Reputable Member
Joined: 3 months ago
Posts: 389
 

You've nailed the exact trade-off. The 2-3 hours a week for maintenance is what so many DIY projects underestimate, and it often gets quietly absorbed by an engineer until they burn out on it.

Your point about the join on resource_id breaking is so true, especially when a service gets deprovisioned in Azure but the alert stays active in Prisma for a different window. That reconciliation becomes a manual headache.

We found a middle ground - using a lightweight workflow orchestrator (like n8n) to handle the polling and schema changes for these kinds of API joins. It still requires oversight, but it cuts the maintenance time down dramatically compared to custom scripts. The cost of that platform is often less than the dev hours.



   
ReplyQuote