Aws Network Monitoring

作者 aws188af2f810ce无许可证2.8K 个星标收录于 2026年10月8日更新于 2026年10月8日仓库今天更新

Installs, configures, and troubleshoots Network Flow Monitor agents on EC2 instances to monitor network path health. Covers agent installation, IAM permissions, monitoring network paths, and troubleshooting agents reporting no metrics, HTTP 403 errors, or connectivity failures.

仅含说明DevOps & Cloud
AI 生成的概览

指导在 EC2 实例上安装、配置 IAM 并排查 CloudWatch Network Flow Monitor 代理问题。

功能
提供在 EC2 实例上安装和配置 Amazon CloudWatch Network Flow Monitor 代理的领域指导,涵盖 IAM 权限设置、通过 SSM Distributor 或命令行安装、激活与验证。它会将用户引导至安装、权限和故障排查的参考文件,并包含关于最小权限 IAM、VPC 端点、凭证存储和 CloudTrail 审计的安全建议。产出的是操作说明和流程,而非脚本或文件。
适用场景
适用于在 EC2 实例上部署 Network Flow Monitor 代理以监控网络路径健康、为代理指标发布配置 IAM 策略,或诊断代理问题(如 HTTP 403 错误、指标缺失或连接失败)的场景。
运行要求
该技能不附带脚本,仅为说明文档。配合 AWS MCP 服务器使用效果最佳,可直接运行 SSM 命令、附加 IAM 策略并验证代理状态,但所有指导也可通过标准 AWS CLI 访问完成。相关流程隐含需要 AWS 账户访问权限、IAM 权限以及对 AWS 服务的网络访问。

AWS Network Monitoring

Overview

Domain expertise for installing and configuring Amazon CloudWatch Network Flow Monitor agents on EC2 instances. Covers IAM permission setup, agent installation via SSM Distributor or command-line install, agent activation, verification, and troubleshooting.

Network Flow Monitor agents are lightweight software that publish performance metrics (latency, packet loss) to the Network Flow Monitor backend, enabling monitoring of network path health between workloads.

Works best with the AWS MCP server — enables running SSM commands, attaching IAM policies, and validating agent status directly. All guidance also works with standard AWS CLI access.

Routing

User needAction
Installing Network Flow Monitor agents on EC2Read agent-install-ec2.md [blocked]
Configuring IAM for Network Flow Monitor agentsRead agent-permissions.md [blocked]
Troubleshooting Network Flow Monitor agents (403, no metrics, connectivity)Read troubleshooting.md [blocked]
Spans multiple areasRead the most specific reference first, then consult others as needed

Files

FileContent
agent-install-ec2.md [blocked]End-to-end Network Flow Monitor agent installation via SSM Distributor, activation, verification
agent-permissions.md [blocked]IAM policy setup for Network Flow Monitor agent metric publishing
troubleshooting.md [blocked]Error → cause → fix for Network Flow Monitor agent issues (HTTP 403, missing metrics, connectivity)

Supported versions

For supported Linux distributions, kernel versions, and architectures, see the AWS documentation. Windows is not supported.

Security Considerations

  • Least-privilege IAM: Attach only CloudWatchNetworkFlowMonitorAgentPublishPolicy for publishing metrics and AmazonSSMManagedInstanceCore for SSM management. Do not use *FullAccess policies.
  • Private subnets: When the instance is in a private subnet, prefer VPC endpoints for SSM (com.amazonaws.<region>.ssm, .ssmmessages, .ec2messages) over a NAT gateway to keep traffic on the AWS network.
  • Credential storage: Never embed AWS credentials on the instance; the publish policy MUST be attached to the instance role, not configured as static keys.
  • Audit trail: Ensure CloudTrail is enabled in the account so SSM SendCommand invocations and IAM AttachRolePolicy actions performed during agent setup are logged for security investigations.
  • References: CloudWatch Network Flow Monitor security, IAM best practices

来源与署名

来源:aws/agent-toolkit-for-aws位于skills/specialized-skills/operations-skills/aws-network-monitoring提交188af2f

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架