Works with what you already run
reCost identifies services from the logs themselves. No SDK, no plugin, no catalog integration, no per-service connector.
An Iceberg table, a Delta table, and an Athena result file leave different signatures in an access log: different prefix structures, different file naming, different user agents, different request patterns. reCost reads those signatures.
Detected automatically
Apache IcebergDelta LakeApache HudiAmazon AthenaTrinoDatabricksRedshift SpectrumApache SparkAWS GlueAWS LambdaAmazon CloudFrontS3 Intelligent-TieringS3 GlacierSageMakerMLflowSTS assumed roles
Findings route to
Microsoft SentinelSplunkSumo LogicGeneric webhookS3 dropJiraServiceNowSlackTeams
Writers and readers,
identified from the log line.
Each request carries the requester ARN and the user agent, which is enough to attribute activity to Glue, Firehose, Kinesis consumers, MSK Connect, Spark, Flink, Trino, Athena, and every SDK version behind them. No CloudTrail data events, so no per-event cost.

One read-only role
covers all of it.
Logs, inventory, and network metadata. Setup takes under an hour.