You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

批量查询AWS账号历史使用服务方案咨询(不含CloudTrail)

Tracking AWS Service Adoption Across Thousands of Accounts (No CloudTrail)

Great question—tracking service adoption across hundreds/thousands of AWS accounts without relying on CloudTrail is a common pain point when monitoring whitelisted service rollouts. Let’s break down the most scalable, actionable approaches that fit your need for clean output (account, service, first use time):

1. Aggregated Cost & Usage Reports (CUR) + Amazon Athena (Best for Large Scale)

This is the most efficient method for thousands of accounts, especially since it leverages AWS-native aggregation without per-account API throttling.

How it works:

  • Enable AWS Organizations if you haven’t already, then set up a shared CUR that aggregates usage data from all member accounts into a single S3 bucket.
  • Use Amazon Athena to query the CUR data directly (AWS provides pre-built table schemas for CUR).
  • The CUR includes fields like line_item_usage_account_id, product_service_code, and line_item_usage_start_date—which you can use to calculate the first time each service was used per account.

Example Athena Query:

SELECT
  line_item_usage_account_id AS account_id,
  product_service_code AS service,
  MIN(line_item_usage_start_date) AS first_use_time
FROM
  your_cur_table_name
WHERE
  product_service_code IN ('<your-whitelisted-services>') -- Optional: filter to your whitelist
GROUP BY
  line_item_usage_account_id, product_service_code
ORDER BY
  account_id, first_use_time;

This will give you exactly the clean, structured output you’re looking for.

2. AWS Service Quotas API + Cross-Account Aggregation

If you need a real-time (or near-real-time) view without waiting for CUR updates, the Service Quotas API can help identify which services are actively being used (since used quotas > 0 indicate service adoption).

How it works:

  • Use AWS Organizations to assume a cross-account role in each member account.
  • For each account, call list_service_quotas and get_service_quota for each whitelisted service to check if any quota is being consumed.
  • Track the first time you detect non-zero usage (you’ll need to store this data over time if you don’t have historical records).

Example Python (Boto3) Snippet:

import boto3
from botocore.exceptions import ClientError

def get_service_usage(account_id, role_arn):
    # Assume cross-account role
    sts_client = boto3.client('sts')
    response = sts_client.assume_role(RoleArn=role_arn, RoleSessionName="ServiceQuotaCheck")
    credentials = response['Credentials']
    
    quotas_client = boto3.client(
        'service-quotas',
        aws_access_key_id=credentials['AccessKeyId'],
        aws_secret_access_key=credentials['SecretAccessKey'],
        aws_session_token=credentials['SessionToken']
    )
    
    whitelisted_services = ['ec2', 'lambda', 's3', 'rds'] # Replace with your list
    usage_data = []
    
    for service in whitelisted_services:
        try:
            quotas = quotas_client.list_service_quotas(ServiceCode=service)
            for quota in quotas['Quotas']:
                if quota['Usage']['Value'] > 0:
                    # You'd need to track the first detection time here (e.g., store in DynamoDB)
                    usage_data.append({
                        'account_id': account_id,
                        'service': service,
                        'first_use_time': '<current-timestamp-or-stored-value>'
                    })
                    break # Stop checking quotas for this service once usage is found
        except ClientError as e:
            print(f"Error checking {service} for {account_id}: {e}")
    return usage_data

# Loop through all accounts in your organization
org_client = boto3.client('organizations')
accounts = org_client.list_accounts()['Accounts']
for account in accounts:
    role_arn = f"arn:aws:iam::{account['Id']}:role/YourCrossAccountRole"
    account_usage = get_service_usage(account['Id'], role_arn)
    # Process or store account_usage as needed

3. AWS Resource Groups Tagging API (For Resource-Level Adoption)

If you specifically want to track when the first resource was created for a service (a strong indicator of service use), the Tagging API lets you fetch resources across services and accounts.

How it works:

  • Assume a cross-account role, then call get_resources with filters for each whitelisted service.
  • Extract the CreationDate attribute from the returned resources and take the earliest date per account/service.

Key Notes:

  • This only works for services that are supported by the Tagging API (most infrastructure services are covered, but some managed services might not be).
  • For thousands of accounts, you’ll want to parallelize these calls to avoid throttling.

Final Recommendations

  • For thousands of accounts: Stick with CUR + Athena—it’s the most scalable and least error-prone method, with built-in historical data.
  • For real-time tracking: Use the Service Quotas API with cross-account roles, paired with a database (like DynamoDB) to track first-use timestamps over time.

All of these methods avoid CloudTrail and give you the exact output you need to measure how quickly your application teams are adopting whitelisted services.

内容的提问来源于stack exchange,提问作者Bartek Malysz

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.09 07:13:12