EC2-Other is the Cost Explorer line where AWS puts EC2 charges other than instance hours. According to the AWS cost management blog, it holds EBS volumes and their snapshots, NAT gateways, some of your data transfer and a few smaller fees.
To see what makes up that amount, filter Cost Explorer to Service = EC2-Other and group the result by Usage type.
Breaking down EC2-Other in Cost Explorer
Open Cost Explorer in the Billing and Cost Management console and set the range to the last six months by month, so you can see which part is growing.
Outside us-east-1, usage types start with a Region code: EUC1- in Frankfurt. The main usage types in EC2-Other:
| Usage type | What it is | What to check |
|---|---|---|
| EBS:VolumeUsage.gp2 and .gp3 | Provisioned volume storage | Unattached volumes and gp2 volumes |
| EBS:SnapshotUsage | Volume snapshots | Snapshots of deregistered AMIs |
| NatGateway-Hours | NAT gateway hours | Number of gateways |
| NatGateway-Bytes | Data processed by NAT | Traffic to S3 and DynamoDB |
| DataTransfer-Regional-Bytes | Traffic between Availability Zones | Services that talk across zones |
Public IPv4 addresses, which older AWS posts list under EC2-Other, now sit under the VPC service. Since 1 February 2024 each one costs about $3.65 a month, even when nothing uses it.
Volumes and snapshots
You pay for the gigabytes a volume has provisioned, even while the instance is stopped. When you terminate an instance, AWS deletes only the root volume by default, so any other volumes stay in the available state and keep costing money. How to list them, and when it pays to move from gp2 to gp3, is in my AWS cost audit checklist.
Deregistering an AMI leaves its snapshots in place by default, so you keep paying for them. When you deregister, tick “Delete associated snapshots” in the console or add --delete-associated-snapshots to aws ec2 deregister-image. A snapshot made together with an image has a description like Created by CreateImage(i-…) for ami-…, so you can check whether that image still exists.
NAT gateways
A NAT gateway is the part of the network that lets servers without a public address reach the internet, for example to download updates. You pay for every hour it runs, even when no traffic goes through it, and separately for every GB it processes.
If NatGateway-Hours dominates, count your gateways. A test environment usually manages with one per VPC. In production, AWS recommends keeping the gateway in the same zone as the resources that send a lot of data through it, because you then avoid cross-zone transfer charges.
When NatGateway-Bytes is the bigger cost, find out where the traffic goes. Traffic to S3 and DynamoDB in the same Region can go through a free gateway endpoint. Once you associate it with the route tables of your private subnets, that traffic stops passing through the NAT gateway. Check your bucket policies first: a condition on the gateway’s address in aws:SourceIp will stop letting that traffic in, because the key is absent for requests through a VPC endpoint, so replace it with an aws:SourceVpce condition.
What it means for a small team
Start with the usage type that grows month after month while your application’s traffic stays flat. If it is NatGateway-Bytes and the application keeps files in S3, add an S3 endpoint first. If it is VolumeUsage or SnapshotUsage, start with the list of available volumes and delete only the ones you are sure nobody needs. If in doubt, take a snapshot first.
Rather than clicking through Cost Explorer, you can load an export of the whole bill grouped by Usage type, without the service filter, into the CSV analysis. The file never leaves your browser, and the analysis shows NAT gateways, traffic between zones, snapshots and gp2 volumes separately when they are a significant part of the bill.
If EC2-Other is a large share of the bill and the usage type split does not explain it, I can go through the account as part of an AWS cost audit.
3 ways I can help
- What I check in an AWS cost audit
Read this post next.
- AWS cost audit
An AWS cost audit at a fixed price per package. You get a list of changes with a saving figure next to each, and I only need read-only access to the account.
- Email me
Or directly to jacob@codelevel.pl. I reply within 1 business day.