PluginBench
Skill
Official
Review
Audit score 70

aws-network-monitoring

aws/agent-toolkit-for-aws

Install and troubleshoot CloudWatch Network Flow Monitor agents on EC2 instances to track network path health.

What is aws-network-monitoring?

Provides domain expertise for deploying Network Flow Monitor agents on EC2 instances, configuring IAM permissions, and troubleshooting agent issues. Use this when setting up network performance monitoring across your EC2 workloads or diagnosing agent connectivity and metric publishing failures.

  • Install Network Flow Monitor agents on EC2 via SSM Distributor or command-line
  • Configure least-privilege IAM policies for agent metric publishing
  • Activate and verify agents are reporting latency and packet loss metrics
  • Troubleshoot HTTP 403 errors, missing metrics, and connectivity failures
  • Set up VPC endpoints for private subnet instances to keep traffic on AWS network

How to install aws-network-monitoring

npx skills add https://github.com/aws/agent-toolkit-for-aws --skill aws-network-monitoring
Prerequisites
  • AWS account with EC2 instances running supported Linux distributions
  • IAM permissions to attach policies to instance roles and run SSM commands
  • EC2 instances with SSM agent installed (or ability to install via SSM Distributor)
  • For private subnets: VPC endpoints for SSM (com.amazonaws.<region>.ssm, .ssmmessages, .ec2messages)
Claude Code
Cursor
Windsurf
Cline

How to use aws-network-monitoring

  1. 1.Identify the EC2 instances where you need Network Flow Monitor agents
  2. 2.Attach the CloudWatchNetworkFlowMonitorAgentPublishPolicy and AmazonSSMManagedInstanceCore policies to the instance IAM role
  3. 3.Use SSM Distributor or command-line to install the Network Flow Monitor agent on each instance
  4. 4.Activate the agent and verify it is reporting metrics in CloudWatch
  5. 5.If agents fail to report metrics or return 403 errors, consult the troubleshooting guide to diagnose IAM, connectivity, or configuration issues

Use cases

Good for
  • Deploy Network Flow Monitor agents across a fleet of EC2 instances to monitor inter-workload network performance
  • Diagnose why agents are not publishing metrics to CloudWatch after installation
  • Configure IAM roles to grant agents permission to publish metrics without overly broad permissions
  • Troubleshoot 403 authorization errors when agents attempt to send data
  • Set up secure agent communication in private subnets using VPC endpoints
Who it's for
  • AWS infrastructure engineers managing EC2 deployments
  • DevOps teams monitoring network path health between services
  • Cloud architects designing least-privilege IAM for monitoring agents
  • SREs troubleshooting network performance issues

aws-network-monitoring FAQ

What is Network Flow Monitor and what does it measure?

Network Flow Monitor is an AWS service that deploys lightweight agents on EC2 instances to publish performance metrics (latency and packet loss) about network paths between workloads, enabling visibility into network health.

Do I need to use the AWS MCP server to use this skill?

No. The skill works best with the AWS MCP server for running SSM commands and validating agent status directly, but all guidance also works with standard AWS CLI access.

What IAM policies should I attach to instances running Network Flow Monitor agents?

Attach CloudWatchNetworkFlowMonitorAgentPublishPolicy for metric publishing and AmazonSSMManagedInstanceCore for SSM management. Never use *FullAccess policies or embed static AWS credentials on the instance.

How do I set up Network Flow Monitor agents in private subnets?

Prefer VPC endpoints for SSM (com.amazonaws.<region>.ssm, .ssmmessages, .ec2messages) over a NAT gateway to keep traffic on the AWS network and reduce data transfer costs.

What Linux distributions and architectures are supported?

See the AWS documentation on supported versions for the latest list of supported Linux distributions, kernel versions, and architectures. Windows is not supported.

Full instructions (SKILL.md)

Source of truth, from aws/agent-toolkit-for-aws.


name: aws-network-monitoring description: >- Installs, configures, and troubleshoots Network Flow Monitor agents on EC2 instances to monitor network path health. Covers agent installation, IAM permissions, monitoring network paths, and troubleshooting agents reporting no metrics, HTTP 403 errors, or connectivity failures. version: 1

AWS Network Monitoring

Overview

Domain expertise for installing and configuring Amazon CloudWatch Network Flow Monitor agents on EC2 instances. Covers IAM permission setup, agent installation via SSM Distributor or command-line install, agent activation, verification, and troubleshooting.

Network Flow Monitor agents are lightweight software that publish performance metrics (latency, packet loss) to the Network Flow Monitor backend, enabling monitoring of network path health between workloads.

Works best with the AWS MCP server — enables running SSM commands, attaching IAM policies, and validating agent status directly. All guidance also works with standard AWS CLI access.

Routing

User needAction
Installing Network Flow Monitor agents on EC2Read agent-install-ec2.md
Configuring IAM for Network Flow Monitor agentsRead agent-permissions.md
Troubleshooting Network Flow Monitor agents (403, no metrics, connectivity)Read troubleshooting.md
Spans multiple areasRead the most specific reference first, then consult others as needed

Files

FileContent
agent-install-ec2.mdEnd-to-end Network Flow Monitor agent installation via SSM Distributor, activation, verification
agent-permissions.mdIAM policy setup for Network Flow Monitor agent metric publishing
troubleshooting.mdError → cause → fix for Network Flow Monitor agent issues (HTTP 403, missing metrics, connectivity)

Supported versions

For supported Linux distributions, kernel versions, and architectures, see the AWS documentation. Windows is not supported.

Security Considerations

  • Least-privilege IAM: Attach only CloudWatchNetworkFlowMonitorAgentPublishPolicy for publishing metrics and AmazonSSMManagedInstanceCore for SSM management. Do not use *FullAccess policies.
  • Private subnets: When the instance is in a private subnet, prefer VPC endpoints for SSM (com.amazonaws.<region>.ssm, .ssmmessages, .ec2messages) over a NAT gateway to keep traffic on the AWS network.
  • Credential storage: Never embed AWS credentials on the instance; the publish policy MUST be attached to the instance role, not configured as static keys.
  • Audit trail: Ensure CloudTrail is enabled in the account so SSM SendCommand invocations and IAM AttachRolePolicy actions performed during agent setup are logged for security investigations.
  • References: CloudWatch Network Flow Monitor security, IAM best practices