Ensure that an Amazon CloudWatch telemetry enablement rule is configured at the organization level to automatically turn on detailed monitoring for the Amazon EC2 instances provisioned within your AWS Organization. CloudWatch telemetry enablement rules let you standardize telemetry collection across your organization by using AWS Config to discover AWS resources and automatically apply the telemetry configuration you define, without requiring you to configure each resource individually. To automatically enable EC2 detailed monitoring across your entire organization, you must create a telemetry enablement rule with the Rule scope set to Organization, the resource type set to AWS::EC2::Instance, and the telemetry type set to Metrics. Organization-level rules are evaluated first in the rule hierarchy, ahead of any organizational unit (OU) or account-level rules, and automatically apply EC2 detailed monitoring (1-minute metric intervals) to existing and newly launched EC2 instances across every member account, in the AWS Regions that the rule targets. Creating and managing organization-level telemetry enablement rules requires trusted access between AWS Organizations and CloudWatch, and can only be performed from the organization's management account or a registered CloudWatch delegated administrator account.
efficiency
excellence
Configuring an organization-wide EC2 detailed monitoring enablement rule removes the operational burden of manually turning on detailed monitoring for every EC2 instance, in every account and Region, across your AWS Organization. Without a centrally enforced rule, EC2 instances default to basic monitoring (5-minute metric intervals), which can delay the detection of performance issues and slow down the reaction time of Amazon EC2 Auto Scaling policies and CloudWatch alarms that depend on more granular data. By enforcing detailed monitoring (1-minute metric intervals) automatically at the organization level, your operations and DevOps teams get consistent, near real-time visibility into EC2 instance performance as soon as instances are launched, without relying on individual account owners to remember to enable the feature.
Note: Amazon EC2 detailed monitoring incurs additional charges based on the number of custom metrics published per instance, unlike basic monitoring, which is provided at no additional cost. Estimate the number of EC2 instances in scope before enabling this rule organization-wide, to forecast the additional monthly Amazon CloudWatch charges (see the References section for current pricing).
Audit
To determine if a CloudWatch telemetry enablement rule is configured to automatically enable Amazon EC2 detailed monitoring across your AWS Organization, perform the following operations:
Remediation / Resolution
To configure a CloudWatch telemetry enablement rule that automatically enables EC2 detailed monitoring across your AWS Organization, perform the following operations:
Note: Creating an organization-level telemetry enablement rule requires trusted access between AWS Organizations and CloudWatch, and telemetry configuration must already be turned on for your organization (see the "Setting up telemetry configuration" reference in the References section for prerequisites). This operation can only be performed from the organization's management account or a registered CloudWatch delegated administrator account. Detailed monitoring metrics generated by this rule are billed according to standard Amazon CloudWatch metrics pricing (see the References section).References
- AWS Documentation
- Telemetry enablement rules
- Telemetry discovery and enablement
- Setting up telemetry configuration
- Basic monitoring and detailed monitoring in CloudWatch
- Amazon CloudWatch Pricing
- AWS Command Line Interface (CLI) Documentation
- list-telemetry-rules-for-organization
- list-telemetry-rules
- get-telemetry-rule-for-organization
- create-telemetry-rule-for-organization