Soru

Zorluk: ZorCloudWatch Dashboards and Container Insights

A SysOps Administrator is setting up cross-account monitoring for containerized workloads. The administrator needs to configure Amazon CloudWatch Container Insights to visualize performance metrics from Amazon ECS clusters running in a source account (Account B) within a centralized dashboard in a monitoring account (Account A). Both accounts are in the same Region. Which of the following actions must the administrator perform to achieve this setup? (Select TWO.)

  1. In the monitoring account (Account A), create a CloudWatch observability sink and define a sink policy that permits Account B to link to it.Cevap
  2. In the source account (Account B), create a CloudWatch observability link pointing to the Amazon Resource Name (ARN) of the sink in Account A.Cevap
  3. C
    In the source account (Account B), modify the CloudWatch agent configuration to specify the regional endpoint of Account A as the primary metric destination.
  4. D
    In the monitoring account (Account A), configure a cross-account IAM role with the CloudWatchAgentServerPolicy policy and configure the ECS tasks in Account B to assume this role.
  5. E
    In the source account (Account B), create a CloudWatch Logs metric filter for the /aws/containerinsights log group that publishes metrics directly to an Amazon Simple Queue Service (Amazon SQS) queue in Account A.

Cevap

To configure cross-account monitoring for Container Insights, you must create a CloudWatch observability sink in the monitoring account (Account A) with a policy permitting Account B, and then create a CloudWatch observability link in the source account (Account B) pointing to the sink in Account A.
To view CloudWatch metrics, logs, and traces from other AWS accounts, CloudWatch cross-account observability uses a sink-and-link model. The monitoring account (receiver) must have a sink and a policy allowing the source account to link to it. The source account (sender) then creates a link referencing the sink. This is the correct, native way to share Container Insights data across accounts.

Adım Adım Çözüm

1
Configure the monitoring account (Account A) as the receiver.
A CloudWatch observability sink is created, and its policy is defined to allow Account B to link to it.
This establishes the monitoring account as a central dashboarding destination that accepts metrics from source accounts.
2
Configure the source account (Account B) as the sender.
A CloudWatch observability link is created in Account B pointing to the ARN of the sink in Account A.
This links Account B's CloudWatch telemetry (including Container Insights) directly to the central monitoring account.
3
Verify and build the dashboard in Account A.
Container Insights metrics from Account B can now be selected and visualized in dashboards within Account A.
Once the link is created, cross-account query capabilities are automatically enabled for the monitoring account.

Anahtar Kavram

CloudWatch Cross-Account Observability using Sinks and Links
Tahmini Süre:2m 0s
Bu soruyu puanla