Works with what you already run

reCost identifies services from the logs themselves. No SDK, no plugin, no catalog integration, no per-service connector.

An Iceberg table, a Delta table, and an Athena result file leave different signatures in an access log: different prefix structures, different file naming, different user agents, different request patterns. reCost reads those signatures.

Detected automatically

Apache IcebergDelta LakeApache HudiAmazon AthenaTrinoDatabricksRedshift SpectrumApache SparkAWS GlueAWS LambdaAmazon CloudFrontS3 Intelligent-TieringS3 GlacierSageMakerMLflowSTS assumed roles

Findings route to

Microsoft SentinelSplunkSumo LogicGeneric webhookS3 dropJiraServiceNowSlackTeams

Writers and readers,
identified from the log line.

Each request carries the requester ARN and the user agent, which is enough to attribute activity to Glue, Firehose, Kinesis consumers, MSK Connect, Spark, Flink, Trino, Athena, and every SDK version behind them. No CloudTrail data events, so no per-event cost.

Identity to client to asset lineage

One read-only role
covers all of it.

Logs, inventory, and network metadata. Setup takes under an hour.