Understand CloudWatch, CloudTrail, and Config by answering WHAT, HOW, and WHO questions

Understand CloudWatch, CloudTrail, and Config by answering WHAT, HOW, and WHO questions

Amazon CloudWatch: WHAT is happening?

CloudWatch is all about monitoring the performance and health of your AWS resources and applications.

  • Purpose: Provides real-time monitoring and observability.
  • Key Features:
  • Collects and tracks metrics
  • Monitors log files
  • Sets alarms
  • Automatically reacts to changes in your AWS resources
  • Use Cases:
  • Monitoring EC2 instance CPU utilization
  • Tracking RDS database connections
  • Setting alarms for billing thresholds
  • Automating actions based on metric thresholds

CloudWatch answers the question: "WHAT is happening in my AWS environment in terms of performance and operational health?"

AWS CloudTrail: WHO did WHAT?

CloudTrail focuses on auditing and tracking user activity and API usage across your AWS infrastructure.

  • Purpose: Provides governance, compliance, and operational auditing.
  • Key Features:
  • Records AWS account activity
  • Tracks user identity
  • Logs the time of actions
  • Stores API call history
  • Use Cases:
  • Tracking changes to AWS resources
  • Investigating security incidents
  • Demonstrating compliance with regulations
  • Troubleshooting operational issues

CloudTrail answers the question: "WHO did WHAT in my AWS account, and WHEN did they do it?"

AWS Config: HOW has my environment changed over time?

AWS Config provides a detailed view of the configuration of AWS resources in your account.

  • Purpose: Assesses, audits, and evaluates the configurations of your AWS resources.
  • Key Features:
  • Records configuration changes over time
  • Evaluate resources against desired configurations
  • Provides compliance auditing
  • Enables security analysis
  • Use Cases:
  • Tracking resource inventory and changes
  • Evaluating compliance with internal policies
  • Troubleshooting configuration changes
  • Simplifying security audits

AWS Config answers the question: "HOW are my resources configured, and HOW has this changed over time?"

Putting It All Together

  • CloudWatch tells you WHAT is happening in real-time with your resources and applications.
  • CloudTrail tells you WHO did WHAT in your AWS account.
  • AWS Config tells you HOW your resources are configured and how they've changed.

By leveraging these three services together, you can gain comprehensive insights into your AWS environment's performance, security, and compliance posture. This approach enables better management, faster troubleshooting, and enhanced security for your AWS infrastructure.

Remember, while each service has its primary focus, there is some overlap in functionality. The key is to use them in combination to get a complete picture of your AWS environment's health, activity, and configuration state.

要查看或添加评论,请登录

Lê Qu?c D?ng的更多文章

  • Making VPCs + On-premises talk to each other - Networking 101

    Making VPCs + On-premises talk to each other - Networking 101

    VPC Peering Privately connect two VPCs using the AWS network. Make them behave as if they were in the same network Two…

  • H?c và thi ch?ng chi AWS Solution Architect Associate hi?u qu?

    H?c và thi ch?ng chi AWS Solution Architect Associate hi?u qu?

    Qu?ng cáo Mình thi ???c 812/1000 ?i?m. C?u trúc ?? thi AWS theo bác Stephene nói thì có 65 cau và có 50 cau tính ?i?m…

    2 条评论
  • NACL - Networking 101

    NACL - Networking 101

    Definition NACLs are like a firewall which control traffic from and to subnets. One NACL per subnet, new subnets are…

  • Daily AWS Solution Architect questions #18

    Daily AWS Solution Architect questions #18

    Q91: A global company is using Amazon API Gateway to design REST APIs for its loyalty club users in the us-east-1…

  • Daily AWS Solution Architect questions #17

    Daily AWS Solution Architect questions #17

    Q81: A company has an automobile sales website that stores its listings in a database on Amazon RDS. When an automobile…

    1 条评论
  • Networking Components & Terms # 1 - Networking 101

    Networking Components & Terms # 1 - Networking 101

    Internet Gateway (IGW) Allow resources (for example EC2 instances) in VPC to connect to the internet. It scales…

    2 条评论
  • Daily AWS Solution Architect questions #16

    Daily AWS Solution Architect questions #16

    Q75: A company wants to migrate an on-premises data center to AWS. The data center hosts an SFTP server that stores its…

    2 条评论
  • Daily AWS Solution Architect questions #15

    Daily AWS Solution Architect questions #15

    Q71: An image-processing company has a web application that users use to upload images. The application uploads the…

  • Daily AWS Solution Architect questions #14

    Daily AWS Solution Architect questions #14

    Q66: A company runs an on-premises application that is powered by a MySQL database. The company is migrating the…

  • VPC & Subnet #1 - Networking 101

    VPC & Subnet #1 - Networking 101

    Default VPC The VPC is automatically created in your account. New EC2 instances are launched into the default VPC if no…

    1 条评论

社区洞察

其他会员也浏览了