aws-network-monitoring
aws/agent-toolkit-for-aws
Install and troubleshoot CloudWatch Network Flow Monitor agents on EC2 instances to track network path health.
What is aws-network-monitoring?
Provides domain expertise for deploying Network Flow Monitor agents on EC2 instances, configuring IAM permissions, and troubleshooting agent issues. Use this when setting up network performance monitoring across your EC2 workloads or diagnosing agent connectivity and metric publishing failures.
- Install Network Flow Monitor agents on EC2 via SSM Distributor or command-line
- Configure least-privilege IAM policies for agent metric publishing
- Activate and verify agents are reporting latency and packet loss metrics
- Troubleshoot HTTP 403 errors, missing metrics, and connectivity failures
- Set up VPC endpoints for private subnet instances to keep traffic on AWS network
How to install aws-network-monitoring
npx skills add https://github.com/aws/agent-toolkit-for-aws --skill aws-network-monitoring- AWS account with EC2 instances running supported Linux distributions
- IAM permissions to attach policies to instance roles and run SSM commands
- EC2 instances with SSM agent installed (or ability to install via SSM Distributor)
- For private subnets: VPC endpoints for SSM (com.amazonaws.<region>.ssm, .ssmmessages, .ec2messages)
How to use aws-network-monitoring
- 1.Identify the EC2 instances where you need Network Flow Monitor agents
- 2.Attach the CloudWatchNetworkFlowMonitorAgentPublishPolicy and AmazonSSMManagedInstanceCore policies to the instance IAM role
- 3.Use SSM Distributor or command-line to install the Network Flow Monitor agent on each instance
- 4.Activate the agent and verify it is reporting metrics in CloudWatch
- 5.If agents fail to report metrics or return 403 errors, consult the troubleshooting guide to diagnose IAM, connectivity, or configuration issues
Use cases
- Deploy Network Flow Monitor agents across a fleet of EC2 instances to monitor inter-workload network performance
- Diagnose why agents are not publishing metrics to CloudWatch after installation
- Configure IAM roles to grant agents permission to publish metrics without overly broad permissions
- Troubleshoot 403 authorization errors when agents attempt to send data
- Set up secure agent communication in private subnets using VPC endpoints
- AWS infrastructure engineers managing EC2 deployments
- DevOps teams monitoring network path health between services
- Cloud architects designing least-privilege IAM for monitoring agents
- SREs troubleshooting network performance issues
aws-network-monitoring FAQ
Network Flow Monitor is an AWS service that deploys lightweight agents on EC2 instances to publish performance metrics (latency and packet loss) about network paths between workloads, enabling visibility into network health.
No. The skill works best with the AWS MCP server for running SSM commands and validating agent status directly, but all guidance also works with standard AWS CLI access.
Attach CloudWatchNetworkFlowMonitorAgentPublishPolicy for metric publishing and AmazonSSMManagedInstanceCore for SSM management. Never use *FullAccess policies or embed static AWS credentials on the instance.
Prefer VPC endpoints for SSM (com.amazonaws.<region>.ssm, .ssmmessages, .ec2messages) over a NAT gateway to keep traffic on the AWS network and reduce data transfer costs.
See the AWS documentation on supported versions for the latest list of supported Linux distributions, kernel versions, and architectures. Windows is not supported.
Full instructions (SKILL.md)
Source of truth, from aws/agent-toolkit-for-aws.
name: aws-network-monitoring description: >- Installs, configures, and troubleshoots Network Flow Monitor agents on EC2 instances to monitor network path health. Covers agent installation, IAM permissions, monitoring network paths, and troubleshooting agents reporting no metrics, HTTP 403 errors, or connectivity failures. version: 1
AWS Network Monitoring
Overview
Domain expertise for installing and configuring Amazon CloudWatch Network Flow Monitor agents on EC2 instances. Covers IAM permission setup, agent installation via SSM Distributor or command-line install, agent activation, verification, and troubleshooting.
Network Flow Monitor agents are lightweight software that publish performance metrics (latency, packet loss) to the Network Flow Monitor backend, enabling monitoring of network path health between workloads.
Works best with the AWS MCP server — enables running SSM commands, attaching IAM policies, and validating agent status directly. All guidance also works with standard AWS CLI access.
Routing
| User need | Action |
|---|---|
| Installing Network Flow Monitor agents on EC2 | Read agent-install-ec2.md |
| Configuring IAM for Network Flow Monitor agents | Read agent-permissions.md |
| Troubleshooting Network Flow Monitor agents (403, no metrics, connectivity) | Read troubleshooting.md |
| Spans multiple areas | Read the most specific reference first, then consult others as needed |
Files
| File | Content |
|---|---|
| agent-install-ec2.md | End-to-end Network Flow Monitor agent installation via SSM Distributor, activation, verification |
| agent-permissions.md | IAM policy setup for Network Flow Monitor agent metric publishing |
| troubleshooting.md | Error → cause → fix for Network Flow Monitor agent issues (HTTP 403, missing metrics, connectivity) |
Supported versions
For supported Linux distributions, kernel versions, and architectures, see the AWS documentation. Windows is not supported.
Security Considerations
- Least-privilege IAM: Attach only
CloudWatchNetworkFlowMonitorAgentPublishPolicyfor publishing metrics andAmazonSSMManagedInstanceCorefor SSM management. Do not use*FullAccesspolicies. - Private subnets: When the instance is in a private subnet, prefer VPC endpoints for SSM (
com.amazonaws.<region>.ssm,.ssmmessages,.ec2messages) over a NAT gateway to keep traffic on the AWS network. - Credential storage: Never embed AWS credentials on the instance; the publish policy MUST be attached to the instance role, not configured as static keys.
- Audit trail: Ensure CloudTrail is enabled in the account so SSM
SendCommandinvocations and IAMAttachRolePolicyactions performed during agent setup are logged for security investigations. - References: CloudWatch Network Flow Monitor security, IAM best practices
Related skills
More from aws/agent-toolkit-for-aws and the wider catalog.

aws-networking
Routes AWS networking requests to the correct service skill for DNS, CDN, hybrid connectivity, and DDoS/WAF protection.

aws-observability
Build, configure, and optimize AWS observability across CloudWatch and CloudWatch Omni with metrics, logs, traces, and alerts.

aws-resilience-lifecycle
Guide end-to-end AWS resilience: Define policies, Test with fault injection, Operate with controls.

aws-sdk-js-v3-usage
AWS SDK for JavaScript v3 development patterns and best practices.

aws-sdk-python-usage
AWS SDK for Python (boto3/botocore) development patterns and best practices.

aws-sdk-swift-usage
AWS SDK for Swift patterns and async client usage for S3, DynamoDB, CloudWatch, and other AWS services.