CloudWatch alarm stuck in INSUFFICIENT_DATA state

Severity
Low
Service
CloudWatch
Check ID
CW_UNUSED_ALARM

What this check finds

An alarm in INSUFFICIENT_DATA state is not receiving metric data — meaning the underlying resource may have been deleted, the metric namespace changed, or the alarm was never properly configured. The alarm continues to incur its monthly charge (~$0.10/alarm/month) without providing any monitoring value.

Passing looks like: No stuck CloudWatch alarms.

How to fix it

Investigate why the alarm lacks data. If the monitored resource no longer exists, delete the alarm: aws cloudwatch delete-alarms --alarm-names ALARM_NAME. If the metric configuration is wrong, update it.

AWS console

CloudWatch → Alarms → filter by state INSUFFICIENT_DATA → review and delete stale alarms.

Compliance

This is an operational hygiene check. It flags something worth tidying rather than a control an auditor asks for, so it is not mapped to a compliance framework.

Checked on every scan

KloudLytics runs this check each time it scans a connected AWS account, through a read-only role, and lists every affected resource with its region. On Pro and Business a fix is written for the specific resource rather than the general case above. The exact access it needs

More CloudWatch checks

All CloudWatch checks

Find out what is actually exposed in your AWS environment.

Connect one AWS account and run your first security assessment.

No credit card · Agentless · Read-only