All skills
aws avatar

/aws-network-monitoring

@eb96852

Installs, configures, and troubleshoots Network Flow Monitor agents on EC2 instances to monitor network path health. Covers agent installation, IAM permissions, monitoring network paths, and troubleshooting agents reporting no metrics, HTTP 403 errors, or connectivity failures.

Use this Skill: https://skilld.dev/gh/aws/agent-toolkit-for-aws/aws-network-monitoring

This session only. Nothing lands on disk.

referencesagent-permissions.md

≈373 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Agent Permissions Setup

Required Policy

Attach the AWS managed policy CloudWatchNetworkFlowMonitorAgentPublishPolicy to the instance role used by your EC2 instances. Without this policy, the agent installs successfully but cannot publish metrics.

Policy ARN: arn:aws:iam::aws:policy/CloudWatchNetworkFlowMonitorAgentPublishPolicy

Attach to existing role

Find the instance role:

PROFILE_ARN=$(aws ec2 describe-instances \
  --instance-ids <instance-id> \
  --query "Reservations[].Instances[].IamInstanceProfile.Arn" \
  --output text)

PROFILE_NAME=$(echo $PROFILE_ARN | awk -F/ '{print $NF}')

ROLE_NAME=$(aws iam get-instance-profile \
  --instance-profile-name $PROFILE_NAME \
  --query "InstanceProfile.Roles[0].RoleName" \
  --output text)

Attach the policy:

aws iam attach-role-policy \
  --role-name $ROLE_NAME \
  --policy-arn arn:aws:iam::aws:policy/CloudWatchNetworkFlowMonitorAgentPublishPolicy

Instance has no instance role yet

If the EC2 instance has no instance profile attached, use the setting-up-ec2-instance-profiles skill first to create the instance role and attach AmazonSSMManagedInstanceCore. Then return here and follow "Attach to existing role" above to add CloudWatchNetworkFlowMonitorAgentPublishPolicy.

Verify

aws iam list-attached-role-policies \
  --role-name <role-name> \
  --query "AttachedPolicies[?PolicyName=='CloudWatchNetworkFlowMonitorAgentPublishPolicy']" \
  --output table

Source: SKILL.md on GitHub

1 warning2mo3 checks · Risk SAFE
  • Gen Agent Trust Hub2mo

    This skill provides instructions for deploying the Amazon CloudWatch Network Flow Monitor agent. It utilizes official AWS package repositories and standard management tools, adhering to established security best practices for IAM and instance management.

  • Socket2mo

    No alerts

  • Snyk2mo

    Risk: MEDIUM · 1 issue

Signed by skilld at eb96852. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago
version
1

README badge

README badge for aws/agent-toolkit-for-aws/aws-network-monitoring