← AWS DevOps Engineer Professional: operations and delivery
06 / 8 · 35 MIN

Telemetry and useful alarms

Distinguish absence, value, and operational-action delivery.

Concept and mechanism

A dashboard is useful only if its signal represents the intended resource and condition. For guest metrics such as memory, configure an appropriate collector, permissions, and destination. Having EC2 CPU does not establish that operating-system collection is ready. Namespace, name, and dimensions identify the series: Environment=prod and Environment=production are not equivalent through intent. Before changing thresholds, confirm points reach the queried series. Then check unit, period, and aggregation. Zero can be a legitimate observation; absence means the expected observation was not received. Confusing them can hide collection failures.

Guided application

Missing-data policy should follow semantics. For a continuous heartbeat, treating absence as notBreaching can hide interruption. For a counter emitting only errors, silence may be normal if emitter health has a separate control. Do not choose the same rule for everything. For M out of N with complete points, count those exceeding the threshold: two of three above 80 triggers with 75, 85, and 90. Composite alarms help combine states and reduce noise but do not directly support Auto Scaling or EC2 actions. Finally, test action delivery. An alarm in ALARM does not prove the recipient received notification or escalation started.

IN PRACTICE

After changing the agent, points disappear but the dashboard stays green. Check collection and service before claiming improvement.

Common pitfalls

Absence as zero; approximate dimension; composite with every action; alarm state as message receipt.

Related topics: Events, incidents, and replay · Security and operational evidence

Take this idea with you

Validate collection, interpretation, and delivery through to the responsible team.

Create account

Reference: CloudWatch alarms · DOP-C02