⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 998+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
Junior / Associate DevOps [L1] Observability Core Fundamentals [L1]

Q: A developer complains that their new logs aren't showing up in CloudWatch. They verified the IAM Role has permission to write logs. What else could be wrong?

If the IAM permissions are correct (i.e., logs:CreateLogStream, logs:PutLogEvents), the issue is often configuration:

#Observability #Observability #L1 #Monitoring #Prometheus #SRE
🎙️ Candidate Opening & Architectural Context
""During a high-traffic production event, our observability stack proved essential in isolating this latency surge. The interviewer is testing: CloudWatch agent configuration, log stream structure.. I structure my answer around systematic triage first, root cause analysis second, and permanent remediation third.""
Advertisement

🛠️ Production Runbook & Step-by-Step Resolution

1️⃣

Initial Diagnostics & Root Cause Analysis

If the IAM permissions are correct (i.e., logs:CreateLogStream, logs:PutLogEvents), the issue is often configuration:

  • Agent Configuration: If using the unified CloudWatch agent on EC2, the /opt/aws/amazon-cloudwatch-agent/etc/amazon-cloudwatch-agent.json must be configured to list the exact absolute path to the log file.
  • Service restart: The agent must be restarted to pick up config file changes.
  • Log Group constraints: If the application creates log streams dynamically, check if the AWS account has hit a rate limit, or if the KMS key encrypting the log group lacks permissions for the compute service to use it.
2️⃣

Remediation & Permanent Safeguards

  • Time synchronization: If the EC2 instance NTP clock is drastically delayed or ahead, CloudWatch will reject the log events stating the timestamps are invalid.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: Agent Configuration: If using the unified CloudWatch agent on EC2, the /opt/aws/amazon-cloudwatch-agent/etc/amazon-cloudwatch-agen."
⚡ 60-Second Elevator Pitch Talking Points
  • Agent Configuration: If using the unified CloudWatch agent on EC2, the /opt/aws/amazon-cloudwatch...
  • Service restart: The agent must be restarted to pick up config file changes.
  • Log Group constraints: If the application creates log streams dynamically, check if the AWS accou...
Advertisement
Want more Observability scenarios?
Explore our complete collection of scenario-based Observability interview runbooks.
Browse All Observability Questions →

📚 Related Production Scenarios in Observability