# Metricbeat AWS Billing Module does not combine Group By options

**URL:** <https://discuss.elastic.co/t/metricbeat-aws-billing-module-does-not-combine-group-by-options/322497>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [January 5, 2023, 1:55am UTC](https://discuss.elastic.co/t/metricbeat-aws-billing-module-does-not-combine-group-by-options/322497 "2023-01-05T01:55:26Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Thomas\_Cate](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thomas_cate/32/115572_2.png) [@Thomas\_Cate](https://discuss.elastic.co/u/Thomas_Cate)\
**Post date:** [January 5, 2023, 1:55am UTC](https://discuss.elastic.co/t/metricbeat-aws-billing-module-does-not-combine-group-by-options/322497/1 "2023-01-05T01:55:26Z")

</div>

It looks like the Metricbeat AWS Billing module takes in an arbitrary number of Cost Explorer Group by Dimensions, and then iterates over them individually to generate documents.

Ideally it should allow you to pair up dimension keys, as you can send 2 at a time to the API. The best example of this, is if you're using a consolidated billing account.

In the current config, you can pull the "SERVICE" and "LINKED\_ACCOUNT" Dimensions. Which gives you two groups of documents.

1. How much you spent per service across all accounts.
2. The total cost of each account.

This means it's impossible to drill down and see a breakdown of what happened in each account.

The AWS API does allow two dimensions in one request. In which case metricbeat would receive every unique pair of Account and Service type. Which would be a much more usefull data set.

---

<div class="post-metadata">

**Author:** ![Thomas\_Cate](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thomas_cate/32/115572_2.png) [@Thomas\_Cate](https://discuss.elastic.co/u/Thomas_Cate)\
**Post date:** [January 5, 2023, 6:16pm UTC](https://discuss.elastic.co/t/metricbeat-aws-billing-module-does-not-combine-group-by-options/322497/2 "2023-01-05T18:16:21Z")

</div>

Taking a second look, it appears that the module is taking 1 group by dimension and 1 group by tag and therefore maxing out the 2 it can have.

Ideally the config should take in pairs(or singles) of group\_by options. Then run against each pair to generate documents.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [January 5, 2023, 7:40pm UTC](https://discuss.elastic.co/t/metricbeat-aws-billing-module-does-not-combine-group-by-options/322497/3 "2023-01-05T19:40:29Z")

</div>

Hi @Thomas_Cate Welcome to the community!

Good insight, perhaps you would consider opening a feature request in the beats repo [here](https://github.com/elastic/beats/issues)

---

<div class="post-metadata">

**Author:** ![Thomas\_Cate](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thomas_cate/32/115572_2.png) [@Thomas\_Cate](https://discuss.elastic.co/u/Thomas_Cate)\
**Post date:** [January 6, 2023, 1:28am UTC](https://discuss.elastic.co/t/metricbeat-aws-billing-module-does-not-combine-group-by-options/322497/4 "2023-01-06T01:28:31Z")

</div>

Sounds good, I opened up a feature request in GH.

> <https://github.com/elastic/beats/issues/34193>
>
> Currently the AWS billing module takes in an arbitrary number of group\_by dimens…ions. However it uses each one individually pairing it with a group\_by tag. Not having multi dimension search makes the data for consolidated billing much less useful.
> 
> For example,
> If you have 10 accounts and you scan your management account with LINKED\_ACCOUNT and SERVICES dimensions.
> With the current AWS Billing Module, you'll get two sets of documents.
> 1. Documents with a summary of total service usage across all accounts.
> 2. Documents with a summary of total bill for each account.
> This means that you cannot drill into how much usage each account had by service.
> 
> Ideally the module would accept pairs of group\_by values. If you pass those same two group\_by dimensions to the api together you get one document per account per service, which allows much deeper filtering.
> 
> There are some more details \[here\](https://discuss.elastic.co/t/metricbeat-aws-billing-module-does-not-combine-group-by-options/322497).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 3, 2023, 3:29am UTC](https://discuss.elastic.co/t/metricbeat-aws-billing-module-does-not-combine-group-by-options/322497/5 "2023-02-03T03:29:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
