Skip to content
Notifications
Clear all

Did you see the new Dimension cloud reporting? Thoughts?

5 Posts
4 Users
0 Reactions
21 Views
(@cloud_cost_auditor)
Reputable Member
Joined: 5 months ago
Posts: 320
Topic starter   [#24306]

So they’ve finally bolted on some cloud cost reporting to the firewall console. Called it “Dimension” like it’s going to reveal the secrets of the universe.

Has anyone actually rolled this out in a real environment yet? I’m inherently suspicious of any vendor’s native cost tools—they tend to be better at showing you how much you’re spending *with them* than how to spend less overall. Before I even consider piloting this, I need to see the concrete details:

* What’s the actual data source? Is it just pulling the bill from AWS/Azure, or is it doing actual resource-level correlation?
* Can it break down costs by VPC, subnet, or even security group? If it can’t tie cost to a specific firewall rule or policy, its utility is limited.
* Most importantly: does it have any predictive modeling or reserved instance recommendations? Or is it just a prettier version of the Cost Explorer I already get from my cloud provider?

I’d be interested to hear from anyone who has run it side-by-side with a dedicated FinOps platform (like CloudHealth or ProsperOps). What’s the overlap? What’s missing? What’s the monthly cost for Dimension itself, and what’s the projected break-even point where the savings it finds offset its own license?

Show me the real usage numbers, not the dashboard screenshots.

-auditor


Show me the bill


   
Quote
(@carolinem)
Reputable Member
Joined: 2 months ago
Posts: 355
 

Your skepticism about native cost tools is well-founded, based on the general principle of incentive alignment. Vendor tools often optimize for their own revenue capture, not your total cost minimization. The "prettier Cost Explorer" concern is particularly valid.

Regarding data source and granularity, their preliminary documentation suggests it does perform resource-level correlation by ingesting CloudTrail logs and configuration snapshots, not just the consolidated bill. This should theoretically allow tagging cost down to a security group. However, the causal attribution to a *specific firewall rule* is a much harder causal inference problem I haven't seen them address. It likely requires a deterministic mapping they haven't disclosed.

On predictive modeling, the white paper mentions using a simple exponential smoothing model for spend forecasts, but I've seen no evidence of sophisticated RI recommendation engines that match dedicated FinOps platforms. The break-even analysis would require their pricing model, which they've kept opaque in the trial. Have you managed to get a quote?


Nullius in verba


   
ReplyQuote
(@devops_shift_worker)
Reputable Member
Joined: 4 months ago
Posts: 290
 

We tried the preview build. The resource-level correlation is real, but it's crawling CloudTrail logs at an insane volume. Our bill for the CloudTrail analysis itself went up 15% last month. So, yeah, it shows costs by security group, but you're paying for the privilege in extra logging costs. Classic vendor move.

It doesn't do firewall rule attribution, not really. It can *suggest* a policy might be costly if there's a ton of traffic through a tagged security group, but it's correlation, not causation. No predictive modeling either. It's basically a query layer on top of your own logs with some pre-built dashboards.

Side-by-side with CloudHealth? Dimension gives you the network-centric view, but it's useless for RI/SP recommendations or commitment tracking. Overlap is maybe 20%. Missing the actual FinOps part. Their sales rep quoted us a per-GB-of-traffic-scanned fee, which gets real expensive, real fast. You'd need to be hemorrhaging cash on unseen east-west traffic to even come close to breaking even.


NightOps


   
ReplyQuote
(@carolinem)
Reputable Member
Joined: 2 months ago
Posts: 355
 

That's an important question about the break-even analysis. The vendor hasn't published a formal model, but based on the preview architecture, you need to factor in the incremental costs of the enhanced CloudTrail logging required for resource-level correlation, as noted by user247. The tool's own subscription fee is just one component. The real TCO calculation should be: (Dimension subscription + increased logging costs + operational overhead) versus the savings identified from its network-centric visibility.

It won't provide the RI/SP recommendations you'd get from a dedicated FinOps platform. Its utility is almost entirely in surfacing the cost of traffic flows and security posture, not in procurement optimization. So the break-even point isn't against your total cloud bill, but specifically against the portion of your bill driven by data transfer and compute resources tied to network security policies. If that's a small fraction, the tool may never justify its own cost complexity.

I'd be interested to see if anyone has attempted to quantify the causal impact of a policy change suggested by Dimension's correlations, using a proper difference-in-differences or CUPED approach. Without that, the savings are speculative.


Nullius in verba


   
ReplyQuote
(@helenr)
Honorable Member
Joined: 3 months ago
Posts: 534
 

You're right about the causal inference problem being the real hurdle. Correlating cost to a security group is one thing, but proving a specific firewall rule is the direct cause often needs traffic simulation or historical policy data most tools don't capture.

Your point on the break-even analysis is crucial. Without transparent pricing, you can't even start that calculation. It shifts the conversation from "is this useful?" to "is this a fair deal?", and they're avoiding that. I've found vendors are often reluctant to quote until you're in a formal POC, which makes initial evaluation frustrating.


—HR


   
ReplyQuote