EBS snapshot older than 30 days — review if still needed

Severity
Low
Service
EBS
Check ID
EBS_OLD_SNAPSHOT

What this check finds

EBS snapshots incur storage charges ($0.05/GB-month for gp2) indefinitely. Snapshots older than 30 days that are not part of an active backup policy are often orphaned or superseded by newer snapshots. Accumulated old snapshots can represent significant unnoticed spend.

Passing looks like: No stale EBS snapshots.

How to fix it

Delete snapshots that are no longer needed: aws ec2 delete-snapshot --snapshot-id SNAPSHOT_ID. Automate snapshot lifecycle with AWS Data Lifecycle Manager.

AWS console

EC2 → Snapshots → filter by creation date → select → Actions → Delete snapshot.

Compliance

This is a cost check. It flags spend that buys nothing, which no compliance framework asks about, so it is not mapped to a control.

Checked on every scan

KloudLytics runs this check each time it scans a connected AWS account, through a read-only role, and lists every affected resource with its region. On Pro and Business a fix is written for the specific resource rather than the general case above. The exact access it needs

Find out what is actually exposed in your AWS environment.

Connect one AWS account and run your first security assessment.

No credit card · Agentless · Read-only