Aws Network Monitoring

作者 aws188af2f810ce無授權條款2.8K 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫今天更新

Installs, configures, and troubleshoots Network Flow Monitor agents on EC2 instances to monitor network path health. Covers agent installation, IAM permissions, monitoring network paths, and troubleshooting agents reporting no metrics, HTTP 403 errors, or connectivity failures.

僅含說明DevOps & Cloud
AI 產生的概覽

指導在 EC2 執行個體上安裝、設定 IAM 並排解 CloudWatch Network Flow Monitor 代理程式問題。

功能
提供在 EC2 執行個體上安裝與設定 Amazon CloudWatch Network Flow Monitor 代理程式的領域指引,涵蓋 IAM 權限設定、透過 SSM Distributor 或命令列安裝、啟用與驗證。它會將使用者導向安裝、權限與疑難排解的參考檔案,並包含關於最小權限 IAM、VPC 端點、憑證儲存與 CloudTrail 稽核的安全建議。產出的是操作說明與流程,而非指令碼或檔案。
適用情境
適用於在 EC2 執行個體上部署 Network Flow Monitor 代理程式以監控網路路徑健康狀態、為代理程式指標發佈設定 IAM 政策,或診斷代理程式問題(例如 HTTP 403 錯誤、指標缺失或連線失敗)的情境。
執行需求
此技能未隨附指令碼,僅為說明文件。搭配 AWS MCP 伺服器使用效果最佳,可直接執行 SSM 命令、附加 IAM 政策並驗證代理程式狀態,但所有指引也可透過標準 AWS CLI 存取完成。相關流程隱含需要 AWS 帳戶存取權、IAM 權限以及對 AWS 服務的網路存取。

AWS Network Monitoring

Overview

Domain expertise for installing and configuring Amazon CloudWatch Network Flow Monitor agents on EC2 instances. Covers IAM permission setup, agent installation via SSM Distributor or command-line install, agent activation, verification, and troubleshooting.

Network Flow Monitor agents are lightweight software that publish performance metrics (latency, packet loss) to the Network Flow Monitor backend, enabling monitoring of network path health between workloads.

Works best with the AWS MCP server — enables running SSM commands, attaching IAM policies, and validating agent status directly. All guidance also works with standard AWS CLI access.

Routing

User needAction
Installing Network Flow Monitor agents on EC2Read agent-install-ec2.md [blocked]
Configuring IAM for Network Flow Monitor agentsRead agent-permissions.md [blocked]
Troubleshooting Network Flow Monitor agents (403, no metrics, connectivity)Read troubleshooting.md [blocked]
Spans multiple areasRead the most specific reference first, then consult others as needed

Files

FileContent
agent-install-ec2.md [blocked]End-to-end Network Flow Monitor agent installation via SSM Distributor, activation, verification
agent-permissions.md [blocked]IAM policy setup for Network Flow Monitor agent metric publishing
troubleshooting.md [blocked]Error → cause → fix for Network Flow Monitor agent issues (HTTP 403, missing metrics, connectivity)

Supported versions

For supported Linux distributions, kernel versions, and architectures, see the AWS documentation. Windows is not supported.

Security Considerations

  • Least-privilege IAM: Attach only CloudWatchNetworkFlowMonitorAgentPublishPolicy for publishing metrics and AmazonSSMManagedInstanceCore for SSM management. Do not use *FullAccess policies.
  • Private subnets: When the instance is in a private subnet, prefer VPC endpoints for SSM (com.amazonaws.<region>.ssm, .ssmmessages, .ec2messages) over a NAT gateway to keep traffic on the AWS network.
  • Credential storage: Never embed AWS credentials on the instance; the publish policy MUST be attached to the instance role, not configured as static keys.
  • Audit trail: Ensure CloudTrail is enabled in the account so SSM SendCommand invocations and IAM AttachRolePolicy actions performed during agent setup are logged for security investigations.
  • References: CloudWatch Network Flow Monitor security, IAM best practices

來源與署名

來源:aws/agent-toolkit-for-aws位於skills/specialized-skills/operations-skills/aws-network-monitoring提交188af2f

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架