If you are deploying the CloudWatch agent in an on-premises environment, you should also install the Systems Manager Agent.
Introduction Last year, after support for Windows 10 ended, I converted a PC that couldn't be upgraded to Windows 11 into a Linux machine (running Ubuntu 24.04). I wasn't sure how to put it to use, but I decided to try setting up a Linux PC management environment as a way to learn about AWS Systems Manager (SSM) and Amazon CloudWatch. One issue I encountered was that the standard procedure for…
When deploying the CloudWatch agent in an on-premises environment, it is recommended to install the Systems Manager Agent as well. CloudWatch Agent gathers metrics, logs, and traces from various instances and servers, allowing monitoring through Amazon CloudWatch. This agent can view metrics like memory usage, CPU usage, and network traffic.
The Systems Manager Agent is necessary for configuring authentication to CloudWatch agent without using long-term access keys. Doing so prevents risks associated with potential AWS environment compromise due to exposed access keys. Instead, the SSM Agent assumes the IAM role associated via hybrid activation to use temporary credentials. This enables uploading logs from an on-premises environment when an IAM policy granting such permission is attached.
To install both agents, first set up a hybrid activation for registering the on-premises device as a managed node. Create a trust policy JSON file and an IAM role with necessary permissions. Attach the AmazonSSMManagedInstanceCore IAM policy for basic SSM functionality and CloudWatchAgentServerPolicy for CloudWatch agent metrics and logs.
Next, create the hybrid activation, specifying an instance name, IAM role name, registration limit, region, and expiration date. Finally, download the SSM Agent and register it as a managed node in AWS Systems Manager.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.