Q: A developer complains that their new logs aren't showing up in CloudWatch. They verified the IAM Role has permission to write logs. What else could be wrong?
If the IAM permissions are correct (i.e., logs:CreateLogStream, logs:PutLogEvents), the issue is often configuration:
#Observability #Observability #L1 #Monitoring #Prometheus #SRE
🎙️ Candidate Opening & Architectural Context
""During a high-traffic production event, our observability stack proved essential in isolating this latency surge. The interviewer is testing: CloudWatch agent configuration, log stream structure.. I structure my answer around systematic triage first, root cause analysis second, and permanent remediation third.""
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
Initial Diagnostics & Root Cause Analysis
If the IAM permissions are correct (i.e., logs:CreateLogStream, logs:PutLogEvents), the issue is often configuration:
- Agent Configuration: If using the unified CloudWatch agent on EC2, the
/opt/aws/amazon-cloudwatch-agent/etc/amazon-cloudwatch-agent.jsonmust be configured to list the exact absolute path to the log file. - Service restart: The agent must be restarted to pick up config file changes.
- Log Group constraints: If the application creates log streams dynamically, check if the AWS account has hit a rate limit, or if the KMS key encrypting the log group lacks permissions for the compute service to use it.
2️⃣
Remediation & Permanent Safeguards
- Time synchronization: If the EC2 instance NTP clock is drastically delayed or ahead, CloudWatch will reject the log events stating the timestamps are invalid.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: Agent Configuration: If using the unified CloudWatch agent on EC2, the /opt/aws/amazon-cloudwatch-agent/etc/amazon-cloudwatch-agen."
⚡ 60-Second Elevator Pitch Talking Points
- Agent Configuration: If using the unified CloudWatch agent on EC2, the /opt/aws/amazon-cloudwatch...
- Service restart: The agent must be restarted to pick up config file changes.
- Log Group constraints: If the application creates log streams dynamically, check if the AWS accou...
Advertisement