Concept and mechanism
An alarm is useful only if it observes the right series and produces an appropriate response. Record namespace, name, dimensions, statistic, period, and missing-data treatment. Instance replacement can leave an alarm watching an old identifier. Low CPU does not exclude memory pressure, disk waits, or a blocked dependency. The CloudWatch agent supports operating-system metrics and logs, but installation, configuration, authorization, and delivery need validation. Missing signals should not automatically be interpreted as a healthy application. The missing-data policy depends on metric meaning and the consequences of the associated action.
Guided application
During diagnosis, choose the source according to the question. CloudTrail helps investigate management calls; AWS Config compares configurations with rules; application logs show observed processing. None replaces all the others. A NON_COMPLIANT evaluation does not establish remediation, and a management-events-only trail does not automatically document S3 object reads. If SSM is offline, correlate agent status and logs with DNS and outbound HTTPS to applicable endpoints. Also test notification arrival at the team: creating an alarm does not establish that someone can receive and execute its response overnight.
The batch ends through OOM with32% CPU. Check guest memory and the instance referenced by the alarm before concluding capacity is sufficient.
Common pitfalls
Confusing missing with zero; trusting stale dimensions; fixing only notification when the series is wrong.
Related topics: Continuity and usable recovery · Changes, drift, and controlled automation · Authorization, keys, and secret consumers
Demonstrate collection, evaluation, delivery, and response as a complete chain.
Reference: CloudWatch agent telemetry collection · SOA-C02 archived guide v2.3; retired2025-09-29