AWS CloudWatch
Amazon CloudWatch is the monitoring and observability service of AWS. It collects data from AWS services and from your applications, and lets you visualize it, set alarms and react automatically.
Key concepts #
- Metrics: time series such as the CPU of an EC2 instance or the requests of a load balancer. AWS services publish metrics automatically (EC2 basic monitoring every 5 minutes, detailed monitoring every 1 minute) and applications can publish custom metrics.
- Alarms: watch a metric and change state when it crosses a threshold. They can notify SNS topics, trigger Auto Scaling policies or run EC2 actions. Composite alarms combine several alarms.
- Logs: log groups and streams that store logs from Lambda, ECS, EKS, VPC Flow Logs, CloudTrail and the CloudWatch agent on servers. Logs Insights queries them, and metric filters turn log lines into metrics.
- Dashboards: graphs of metrics, logs and alarms, also across accounts and Regions.
- Events: Amazon EventBridge (the evolution of CloudWatch Events) routes events from AWS services, schedules and SaaS partners to targets such as Lambda.
- Application and infrastructure monitoring: Container Insights, Lambda Insights, Application Signals, Synthetics canaries and RUM.
Pricing #
Pay per custom metric, alarm, dashboard, GB of logs ingested and stored, and queries. Many AWS service metrics are free. See the CloudWatch pricing.
With Terraform #
The resources are aws_cloudwatch_metric_alarm, aws_cloudwatch_log_group, aws_cloudwatch_log_metric_filter, aws_cloudwatch_dashboard and aws_cloudwatch_event_rule.
See also: AWS CloudTrail records who did what; CloudWatch records how the systems behave.