CloudGuard is a cloud native security platform that provides advanced network security, threat prevention, workload protection, and compliance across public cloud environments. CloudGuard deployments typically consist of security gateways, clustered firewalls, policy-based security configurations, and autoscaling resources that run on cloud infrastructure.
Since CloudGuard relies on cloud services such as compute instances, storage, networking, and data transfer, the associated infrastructure costs are billed by the cloud provider rather than CloudGuard itself. As CloudGuard environments grow across multiple cloud platforms, applications, and regions, identifying the source of these costs becomes increasingly difficult.
ManageEngine CloudSpend provides a unified view of CloudGuard-related cloud spending across AWS, Azure, and GCP by identifying resources using predefined CloudGuard tags. It maps cloud billing data to these tagged resources and aggregates the associated costs, enabling you to monitor spending, understand cost drivers, and optimize your cloud security infrastructure.
CloudGuard cost management is the process of tracking, analyzing, and optimizing the cloud infrastructure costs associated with CloudGuard deployments.
In CloudSpend, this is achieved by using CloudGuard-specific tags applied to cloud resources. These tags associate cloud infrastructure costs with logical CloudGuard entities such as clusters, policy groups, and autoscaling groups, even though the actual charges originate from AWS, Azure, or GCP.
Effective CloudGuard cost management involves:
CloudSpend simplifies CloudGuard cost management across AWS, Azure, and GCP by combining cloud billing information with tagged resource usage.
Instead of manually mapping cloud infrastructure to CloudGuard deployments, CloudSpend identifies CloudGuard related resources using predefined tags such as Cluster ID, Policy Group, and Autoscaling Group Name. It then maps cloud costs to these logical entities, providing meaningful visibility into CloudGuard infrastructure spending.
This enables you to:
CloudSpend also separates CloudGuard related costs from other cloud workloads, enabling you to determine whether spending changes are driven by security infrastructure, scaling activities, or supporting cloud services.
Trend analysis and anomaly detection help identify unexpected spending patterns. For example, if additional CloudGuard gateways are automatically deployed in response to increased network traffic, the resulting infrastructure costs are immediately reflected in the report.
You can also configure budgets and alerts based on CloudGuard tagged resources, enabling proactive cost monitoring and faster response to unexpected cloud spending.
By organizing cloud costs using CloudGuard-specific tags, CloudSpend transforms raw cloud billing data into actionable insights for your cloud security deployments.
CloudSpend uses the following entities to identify and track your CloudGuard resources across AWS, Azure, and GCP environments.
| Report category | Report display name | Description | Tag key | Tag value |
|---|---|---|---|---|
| CloudGuard | Cluster ID | The CloudGuard cluster ID | cloudguard:cluster-id | <cluster-id> |
| CloudGuard | Policy Group | The CloudGuard policy group | cloudguard:policy-group | <policy-group> |
| CloudGuard | Autoscaling Group | The CloudGuard autoscaling group | cloudguard:asg-name | <autoscaling-group> |
These tags are used to group cloud costs and provide detailed cost visibility based on how your CloudGuard security infrastructure is organized.
CloudSpend uses the entities cited in the table above to identify and track your CloudGuard resources across AWS, Azure, and GCP environments. These tags connect cloud billing data with your CloudGuard security infrastructure, making it easier to understand how cloud costs are distributed across different security deployments.
The Cluster ID tag represents a CloudGuard security cluster that provides high availability and network protection. CloudSpend uses this tag to aggregate infrastructure costs for each cluster, enabling you to compare spending across different security deployments and identify clusters with higher operational costs.
The Policy Group tag represents the collection of security policies applied to CloudGuard gateways. CloudSpend uses this tag to associate cloud costs with policy-driven deployments, helping you understand how different security configurations contribute to infrastructure spending.
The Autoscaling Group tag identifies CloudGuard gateways that automatically scale based on network traffic or security demand. CloudSpend tracks the infrastructure costs associated with these dynamically provisioned resources, empowering you to evaluate whether autoscaling activities are operating efficiently and contributing appropriately to cloud spend.
By organizing cloud costs using these CloudGuard-specific tags, CloudSpend delivers granular cost attribution across your cloud security infrastructure. You can analyze costs by cluster, policy group, autoscaling group, compare deployment costs, identify high-cost security environments, and optimize resource allocation without manually correlating cloud billing information.
Here are some of the key benefits of the CloudGuard cost report:
The CloudGuard cost report provides a centralized view of cloud infrastructure costs associated with your CloudGuard deployments across AWS, Azure, and GCP.
By combining cloud billing information with CloudGuard specific resource tags, the report helps you understand how infrastructure costs are distributed across clusters, policy groups, and autoscaling deployments. This enables you to identify cost trends, compare security environments, and make informed decisions to optimize your cloud security infrastructure.
Follow these steps to view the report:
1. Log in to CloudSpend and go to Reports.
2. Select the CloudGuard cost report.
3. Use filters to narrow down by account, region, or resource.
4. Select the required account to view the Spend Analysis dashboard.
The Spend Analysis view provides a consolidated overview of the cloud costs associated with your CloudGuard deployments across AWS, Azure, and GCP. It combines billing information with tagged CloudGuard resources, allowing you to understand where your cloud security budget is being consumed without manually analyzing cloud provider invoices.
From this view, you can monitor the total cloud cost for the selected time period, identify the highest spending cloud accounts, subscriptions, or projects, and detect anomalies that indicate unexpected cost increases.
You can also analyze cost distribution across services, regions, resource groups, and cloud accounts to understand how different infrastructure components contribute to overall spending. Trend analysis helps you compare costs over time and identify periods where CloudGuard infrastructure costs increased or decreased.
Since CloudSpend attributes costs using CloudGuard specific tags, you can quickly determine whether changes in spending are associated with a particular cluster, policy group, or autoscaling group. This helps reduce the time required to investigate unexpected infrastructure costs and provides better visibility into cloud security spending.
The Resource Explorer provides a detailed view of how cloud costs are distributed across your CloudGuard infrastructure. It enables you to analyze tagged resources from multiple perspectives, helping you identify cost drivers and improve infrastructure planning.
You can analyze cloud costs across accounts, subscriptions, projects, services, regions, resource groups, and tags, depending on the cloud provider. This flexibility allows you to understand cost ownership at different organizational levels while maintaining visibility into your CloudGuard deployments.
The Resource Explorer also enables you to group costs using CloudGuard specific tags such as Cluster ID, Policy Group, and Autoscaling Group. This makes it easier to attribute cloud spending to logical CloudGuard deployments and evaluate the infrastructure cost of individual security environments.
In addition, you can monitor total costs for a selected period, evaluate historical spending trends, and apply filters to focus on specific cloud providers, regions, services, or tagged deployments.
By allowing you to explore cost data across multiple dimensions, the Resource Explorer helps improve financial accountability, simplify cost analysis, and identify opportunities to optimize your CloudGuard infrastructure while maintaining consistent security coverage.