All skills
aws avatar

/aws-network-monitoring

@eb96852

Installs, configures, and troubleshoots Network Flow Monitor agents on EC2 instances to monitor network path health. Covers agent installation, IAM permissions, monitoring network paths, and troubleshooting agents reporting no metrics, HTTP 403 errors, or connectivity failures.

Use this Skill: https://skilld.dev/gh/aws/agent-toolkit-for-aws/aws-network-monitoring

This session only. Nothing lands on disk.

referencestroubleshooting.md

≈611 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Troubleshooting Network Flow Monitor

SSM command fails or instance not reachable via SSM

Verify the SSM Agent is running on the instance and the instance can reach SSM endpoints. For isolated subnets, ensure VPC endpoints for SSM (com.amazonaws.<region>.ssm, .ssmmessages, .ec2messages) are configured. The instance role also needs AmazonSSMManagedInstanceCore attached.

Agent installed but never activated (SSM path only)

Installation and activation are separate steps when using the SSM Distributor path. After installing via SSM Distributor, you must explicitly activate the agent using the AmazonCloudWatch-NetworkFlowMonitorManageAgent SSM document with Action: Activate. See agent-install-ec2.md Step 4.

This does NOT apply to command-line installs (yum/apt-get). Agents installed via command-line begin publishing as soon as the package is installed and the IAM policy is attached — no activation step is needed.

Stopping and starting the agent

sudo service network-flow-monitor stop
sudo service network-flow-monitor start

Verify agent status

sudo service network-flow-monitor status

Verify endpoint connectivity and IAM permissions

Check agent logs for HTTP errors:

sudo journalctl -f -u network-flow-monitor.service | grep -i HTTP

Any status code other than 200 indicates an error.

HTTP 403 — Missing/insufficient IAM permissions

{
    "level": "INFO",
    "message": "HTTP request complete",
    "status": 403,
    "target": "nfm_agent::reports::publisher_endpoint",
    "timestamp": "XXXX"
}

Fix: Attach CloudWatchNetworkFlowMonitorAgentPublishPolicy to the instance role. See agent-permissions.md.

Connection error — Network connectivity issue

{
    "level": "ERROR",
    "message": "Error sending request: error sending request for url (https://networkflowmonitorreports.<region>.api.aws/publish)",
    "target": "nfm_agent::reports::publisher_endpoint",
    "timestamp": "XXXX"
}

Fix: Verify connectivity to the Network Flow Monitor endpoint:

nc -zv networkflowmonitorreports.<region>.api.aws 443

Or perform an authenticated TLS check:

curl -v https://networkflowmonitorreports.<region>.api.aws/

If using private subnets, ensure a VPC endpoint or NAT gateway is configured for the Network Flow Monitor service endpoint.

Source: SKILL.md on GitHub

1 warning2mo3 checks · Risk SAFE
  • Gen Agent Trust Hub2mo

    This skill provides instructions for deploying the Amazon CloudWatch Network Flow Monitor agent. It utilizes official AWS package repositories and standard management tools, adhering to established security best practices for IAM and instance management.

  • Socket2mo

    No alerts

  • Snyk2mo

    Risk: MEDIUM · 1 issue

Signed by skilld at eb96852. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago
version
1

README badge

README badge for aws/agent-toolkit-for-aws/aws-network-monitoring