Info icon
End of Life Notice: For Trend Cloud One™ - Conformity Customers, Conformity will reach its End of Sale on “July 31st, 2025” and End of Life “July 31st, 2026”. The same capabilities and much more is available in TrendAI Vision One™ Cloud Risk Management. For details, please refer to Upgrade to TrendAI Vision One™

CloudWatch Organization-Wide EC2 Detailed Monitoring Enablement

TrendAI Vision One™ provides continuous assurance that gives peace of mind for your cloud infrastructure, delivering over 1400 automated best practice checks.

Risk Level: Medium (should be achieved)

Ensure that an Amazon CloudWatch telemetry enablement rule is configured at the organization level to automatically turn on detailed monitoring for the Amazon EC2 instances provisioned within your AWS Organization. CloudWatch telemetry enablement rules let you standardize telemetry collection across your organization by using AWS Config to discover AWS resources and automatically apply the telemetry configuration you define, without requiring you to configure each resource individually. To automatically enable EC2 detailed monitoring across your entire organization, you must create a telemetry enablement rule with the Rule scope set to Organization, the resource type set to AWS::EC2::Instance, and the telemetry type set to Metrics. Organization-level rules are evaluated first in the rule hierarchy, ahead of any organizational unit (OU) or account-level rules, and automatically apply EC2 detailed monitoring (1-minute metric intervals) to existing and newly launched EC2 instances across every member account, in the AWS Regions that the rule targets. Creating and managing organization-level telemetry enablement rules requires trusted access between AWS Organizations and CloudWatch, and can only be performed from the organization's management account or a registered CloudWatch delegated administrator account.

Reliability
Performance
efficiency
Operational
excellence

Configuring an organization-wide EC2 detailed monitoring enablement rule removes the operational burden of manually turning on detailed monitoring for every EC2 instance, in every account and Region, across your AWS Organization. Without a centrally enforced rule, EC2 instances default to basic monitoring (5-minute metric intervals), which can delay the detection of performance issues and slow down the reaction time of Amazon EC2 Auto Scaling policies and CloudWatch alarms that depend on more granular data. By enforcing detailed monitoring (1-minute metric intervals) automatically at the organization level, your operations and DevOps teams get consistent, near real-time visibility into EC2 instance performance as soon as instances are launched, without relying on individual account owners to remember to enable the feature.

Note: Amazon EC2 detailed monitoring incurs additional charges based on the number of custom metrics published per instance, unlike basic monitoring, which is provided at no additional cost. Estimate the number of EC2 instances in scope before enabling this rule organization-wide, to forecast the additional monthly Amazon CloudWatch charges (see the References section for current pricing).


Audit

To determine if a CloudWatch telemetry enablement rule is configured to automatically enable Amazon EC2 detailed monitoring across your AWS Organization, perform the following operations:

Using AWS Console

  1. Sign in to the AWS Management Console using the organization's management account or a registered CloudWatch delegated administrator account.

  2. Navigate to Amazon CloudWatch console at https://console.aws.amazon.com/cloudwatch/.

  3. In the navigation pane, choose Ingestion.

  4. Choose the Enablement rules tab to list the telemetry enablement rules configured for your AWS account and organization.

  5. Filter the list of enablement rules by choosing Data source as a filter property and selecting Amazon EC2 as the value, to narrow the results down to only the enablement rules that target Amazon EC2 instances.

  6. Check whether any rules are returned by the filter, and check the Account scope and Telemetry type columns for each. If the filter returns no rules, or if none of the listed rules have Account scope set to Organization and Telemetry type set to Detailed metrics, there is no organization-level enablement rule configured for EC2 detailed monitoring.

  7. If a rule matching this configuration is listed, click on the rule name (link) to open the rule details page and confirm that the Resource type attribute is set to AWS::EC2::Instance, the Telemetry type attribute is set to Detailed metrics, and the Account scope attribute is set to Organization.

  8. On the rule details page, check the Target regions attribute value. If the value is not set to All regions, note the specific AWS Regions covered by the rule.

  9. Change the AWS Region from the console navigation bar and repeat steps no. 4 – 8 to confirm that an equivalent EC2 detailed monitoring rule is available (either replicated automatically or created independently) in other AWS Regions where EC2 instances are deployed within your organization.

Using AWS CLI

  1. Run list-telemetry-rules-for-organization command (OSX/Linux/UNIX) from the organization's management account or a delegated administrator account, with output query filters, to list the organization-level telemetry rules configured for EC2 detailed monitoring in the current AWS Region:

    aws observabilityadmin list-telemetry-rules-for-organization
    --region us-east-1
    --query "TelemetryRuleSummaries[?ResourceType=='AWS::EC2::Instance' && TelemetryType=='Metrics']"
    
  2. The command output should return the requested rule summaries:

    [
        {
            "RuleName": "cc-org-ec2-detailed-monitoring",
            "RuleArn": "arn:aws:observabilityadmin:us-east-1:123456789012:organization-telemetry-rule/cc-org-ec2-detailed-monitoring",
            "CreatedTimeStamp": 1774000000,
            "LastUpdateTimeStamp": 1774000000,
            "ResourceType": "AWS::EC2::Instance",
            "TelemetryType": "Metrics"
        }
    ]
    

    If the list-telemetry-rules-for-organization command output returns an empty array (i.e. []), there is no organization-level telemetry enablement rule configured for EC2 detailed monitoring in the selected AWS Region.

  3. Run get-telemetry-rule-for-organization command (OSX/Linux/UNIX) using the name (or ARN) of the rule returned at the previous step as the identifier parameter, to describe the rule's configuration in full. Use get-telemetry-rule-for-organization, not get-telemetry-rule — the latter only reads account-scoped rules and returns a ResourceNotFoundException for organization-scoped rules, even when the rule exists:

    aws observabilityadmin get-telemetry-rule-for-organization
    --region us-east-1
    --rule-identifier cc-org-ec2-detailed-monitoring
    
  4. The command output should return the rule configuration metadata:

    {
        "RuleName": "cc-org-ec2-detailed-monitoring",
        "RuleArn": "arn:aws:observabilityadmin:us-east-1:123456789012:organization-telemetry-rule/cc-org-ec2-detailed-monitoring",
        "CreatedTimeStamp": 1774000000,
        "LastUpdateTimeStamp": 1774000000,
        "TelemetryRule": {
            "ResourceType": "AWS::EC2::Instance",
            "TelemetryType": "Metrics",
            "Regions": [
                "us-east-2",
                "us-west-1",
                "us-west-2"
            ],
            "AllRegions": true
        },
        "HomeRegion": "us-east-1",
        "RegionStatuses": [
            {
                "Region": "us-east-2",
                "Status": "ACTIVE",
                "RuleArn": "arn:aws:observabilityadmin:us-east-2:123456789012:organization-telemetry-rule/cc-org-ec2-detailed-monitoring"
            }
        ]
    }
    

    Because the rule was successfully retrieved using the get-telemetry-rule-for-organization command (the organization-specific API operation), its existence there already confirms that it is an organization-level rule. If the list-telemetry-rules-for-organization command at step no. 1 returned an empty array, or if get-telemetry-rule-for-organization returns a ResourceNotFoundException, there is no organization-level telemetry enablement rule for EC2 detailed monitoring.

  5. Check the "AllRegions" property value returned at the previous step. If the value is set to true, the rule automatically covers every AWS Region, including Regions you opt into in the future. If the value is set to false, review the rule's "Regions" property to identify the specific AWS Regions covered by the rule.

  6. Check the "Status" value for each entry in the "RegionStatuses" list. If any Region shows a "Status" of FAILED rather than ACTIVE, EC2 detailed monitoring replication did not succeed for that Region, and the "FailureReason" property (also returned for that entry) describes why.

  7. Repeat steps no. 1 – 6 for each AWS Region where EC2 instances are deployed within your organization, by updating the --region command parameter value, to confirm that the rule (or its replicated copy) is available in that Region.

Remediation / Resolution

To configure a CloudWatch telemetry enablement rule that automatically enables EC2 detailed monitoring across your AWS Organization, perform the following operations:

Note: Creating an organization-level telemetry enablement rule requires trusted access between AWS Organizations and CloudWatch, and telemetry configuration must already be turned on for your organization (see the "Setting up telemetry configuration" reference in the References section for prerequisites). This operation can only be performed from the organization's management account or a registered CloudWatch delegated administrator account. Detailed monitoring metrics generated by this rule are billed according to standard Amazon CloudWatch metrics pricing (see the References section).

Using AWS Console

  1. Sign in to the AWS Management Console using the organization's management account or a registered CloudWatch delegated administrator account.

  2. Navigate to Amazon CloudWatch console at https://console.aws.amazon.com/cloudwatch/.

  3. In the navigation pane, choose Ingestion.

  4. Choose the Enablement rules tab (see Audit section part I to confirm no equivalent rule already exists).

  5. Choose Add rule.

  6. For Data source, select Amazon EC2, then choose Configure.

  7. For Rule name, enter a unique name for the new rule, e.g. cc-org-ec2-detailed-monitoring.

  8. For Account scope, choose Organization, to apply the rule across your entire AWS Organization.

  9. For Telemetry type, select Detailed metrics to enable EC2 detailed monitoring.

  10. (Optional) For Target regions, turn on the All regions option to automatically apply the rule to every AWS Region where EC2 instances are running, including Regions you opt into in the future.

  11. Choose Create rule to apply the changes. CloudWatch uses AWS Config to discover the EC2 instances across your organization that don't already have detailed monitoring enabled, and automatically enables the feature for those instances (the initial discovery may take up to 24 hours to complete).

  12. If you did not select All regions at step no. 10, change the AWS Region from the console navigation bar and repeat steps no. 5 – 11 for the other AWS Regions where EC2 instances are deployed within your organization.

Using AWS CLI

  1. Run create-telemetry-rule-for-organization command (OSX/Linux/UNIX) from the organization's management account or a delegated administrator account, to create the organization-wide telemetry enablement rule for EC2 detailed monitoring (see Audit section part II to confirm no equivalent rule already exists):

    aws observabilityadmin create-telemetry-rule-for-organization
    --region us-east-1
    --rule-name cc-org-ec2-detailed-monitoring
    --rule '{
        "ResourceType": "AWS::EC2::Instance",
        "TelemetryType": "Metrics",
        "AllRegions": true
    }'
    
  2. The command output should return the ARN of the newly created organization-level telemetry rule:

    {
        "RuleArn": "arn:aws:observabilityadmin:us-east-1:123456789012:organization-telemetry-rule/cc-org-ec2-detailed-monitoring"
    }
    
  3. Run get-telemetry-rule-for-organization command (OSX/Linux/UNIX) to verify that the rule was successfully created as an organization-level rule. Use get-telemetry-rule-for-organization, not the account-scoped get-telemetry-rule command, which returns a ResourceNotFoundException for organization-scoped rules:

    aws observabilityadmin get-telemetry-rule-for-organization
    --region us-east-1
    --rule-identifier cc-org-ec2-detailed-monitoring
    
  4. The command output should confirm the requested configuration:

    {
        "RuleName": "cc-org-ec2-detailed-monitoring",
        "RuleArn": "arn:aws:observabilityadmin:us-east-1:123456789012:organization-telemetry-rule/cc-org-ec2-detailed-monitoring",
        "TelemetryRule": {
            "ResourceType": "AWS::EC2::Instance",
            "TelemetryType": "Metrics",
            "Regions": [
                "us-east-2",
                "us-west-1",
                "us-west-2"
            ],
            "AllRegions": true
        },
        "HomeRegion": "us-east-1",
        "RegionStatuses": [
            {
                "Region": "us-east-2",
                "Status": "ACTIVE",
                "RuleArn": "arn:aws:observabilityadmin:us-east-2:123456789012:organization-telemetry-rule/cc-org-ec2-detailed-monitoring"
            }
        ]
    }
    

    Successfully retrieving the rule through get-telemetry-rule-for-organization confirms it was created at the organization level. Check the "Status" value for each entry in "RegionStatuses" — every targeted Region should show ACTIVE once replication completes.

  5. If you did not set the "AllRegions" property to true at step no. 1, repeat steps no. 1 – 4 for the other AWS Regions where EC2 instances are deployed within your organization, by updating the --region command parameter value.

References

Publication date Sep 23, 2026