The Billion-Byte Billing Surprise
When our team audited the AWS bill for a fast-growing FinTech client, one line item jumped off the page: CloudWatch Data Ingestion. They were spending nearly $4,000 a month simply to log HTTP requests and application traces. As their microservices architecture scaled on Amazon EKS, their logging volume grew exponentially, transforming CloudWatch from a helpful tool into a massive financial drain.
CloudWatch is incredibly convenient out-of-the-box, but at $0.50 per GB for ingestion, high-throughput microservices can generate crippling bills overnight.
The Solution: OpenTelemetry + Grafana Loki
We proposed entirely bypassing CloudWatch for application logs. Instead, we architected a self-hosted observability pipeline natively within their existing Kubernetes clusters.
We deployed OpenTelemetry (OTel) Collectors as DaemonSets on the EKS worker nodes. These collectors intercept application logs, metrics, and traces at the edge, batch them, and ship them to a highly-available Grafana Loki cluster backed by cheap AWS S3 storage.
Why Loki?
Unlike Elasticsearch, which indexes the full text of logs and requires massive, expensive EC2 instances with tons of RAM, Loki only indexes metadata (labels). This makes Loki incredibly resource-efficient and cheap to operate, as the raw log data is shoved directly into S3 for pennies per gigabyte.
The Implementation Phase
- Step 1: OTel Collector Deployment. We used Terraform to deploy the OpenTelemetry Operator and configure pipelines to scrape logs directly from the Docker container runtimes.
- Step 2: Log Filtering. We implemented regex-based filtering at the OTel layer to aggressively drop repetitive, low-value debug logs before they even hit the network.
- Step 3: Loki & S3 Backend. We deployed Grafana Loki using Helm, configuring it to use a dedicated S3 bucket for persistent storage and DynamoDB for the index.
The Results Speak Volumes
Within 24 hours of cutting over, the CloudWatch ingestion metrics flatlined. Our new observability stack cost approximately $450/month in EC2 compute and S3 storage, completely replacing the $4,000/month CloudWatch bill.
Final Outcomes:
- 60% reduction in total AWS observability costs.
- Sub-second query performance using LogQL in Grafana.
- Vendor-neutral telemetry instrumentation thanks to OpenTelemetry.


