Aws Network Monitoring

by aws188af2f810ceNo license2.8K starsListed Oct 8, 2026Updated Oct 8, 2026Repository updated today

Installs, configures, and troubleshoots Network Flow Monitor agents on EC2 instances to monitor network path health. Covers agent installation, IAM permissions, monitoring network paths, and troubleshooting agents reporting no metrics, HTTP 403 errors, or connectivity failures.

Instructions onlyDevOps & Cloud
AI-generated overview

Guides installation, IAM setup, and troubleshooting of CloudWatch Network Flow Monitor agents on EC2 instances.

What it does
Provides domain guidance for installing and configuring Amazon CloudWatch Network Flow Monitor agents on EC2 instances, covering IAM permission setup, installation via SSM Distributor or command line, activation, and verification. It routes the user to reference files for installation, permissions, and troubleshooting, and includes security guidance on least-privilege IAM, VPC endpoints, credential storage, and CloudTrail auditing. It produces instructions and procedures rather than scripts or files.
When to use it
Use when deploying Network Flow Monitor agents to EC2 instances to monitor network path health, when configuring IAM policies for agent metric publishing, or when diagnosing agent problems such as HTTP 403 errors, missing metrics, or connectivity failures.
Requirements
No scripts ship with the skill; it is instructions only. It works best with the AWS MCP server for running SSM commands, attaching IAM policies, and validating agent status, but all guidance also works with standard AWS CLI access. AWS account access, IAM permissions, and network access to AWS services are implied by the procedures.

AWS Network Monitoring

Overview

Domain expertise for installing and configuring Amazon CloudWatch Network Flow Monitor agents on EC2 instances. Covers IAM permission setup, agent installation via SSM Distributor or command-line install, agent activation, verification, and troubleshooting.

Network Flow Monitor agents are lightweight software that publish performance metrics (latency, packet loss) to the Network Flow Monitor backend, enabling monitoring of network path health between workloads.

Works best with the AWS MCP server — enables running SSM commands, attaching IAM policies, and validating agent status directly. All guidance also works with standard AWS CLI access.

Routing

User needAction
Installing Network Flow Monitor agents on EC2Read agent-install-ec2.md [blocked]
Configuring IAM for Network Flow Monitor agentsRead agent-permissions.md [blocked]
Troubleshooting Network Flow Monitor agents (403, no metrics, connectivity)Read troubleshooting.md [blocked]
Spans multiple areasRead the most specific reference first, then consult others as needed

Files

FileContent
agent-install-ec2.md [blocked]End-to-end Network Flow Monitor agent installation via SSM Distributor, activation, verification
agent-permissions.md [blocked]IAM policy setup for Network Flow Monitor agent metric publishing
troubleshooting.md [blocked]Error → cause → fix for Network Flow Monitor agent issues (HTTP 403, missing metrics, connectivity)

Supported versions

For supported Linux distributions, kernel versions, and architectures, see the AWS documentation. Windows is not supported.

Security Considerations

  • Least-privilege IAM: Attach only CloudWatchNetworkFlowMonitorAgentPublishPolicy for publishing metrics and AmazonSSMManagedInstanceCore for SSM management. Do not use *FullAccess policies.
  • Private subnets: When the instance is in a private subnet, prefer VPC endpoints for SSM (com.amazonaws.<region>.ssm, .ssmmessages, .ec2messages) over a NAT gateway to keep traffic on the AWS network.
  • Credential storage: Never embed AWS credentials on the instance; the publish policy MUST be attached to the instance role, not configured as static keys.
  • Audit trail: Ensure CloudTrail is enabled in the account so SSM SendCommand invocations and IAM AttachRolePolicy actions performed during agent setup are logged for security investigations.
  • References: CloudWatch Network Flow Monitor security, IAM best practices

Source and attribution

Source:aws/agent-toolkit-for-awsinskills/specialized-skills/operations-skills/aws-network-monitoringat commit188af2f

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal

Aws Network Monitoring Agent Skill | SourceWeft