Question 1 · choose 1
An engineer added /var/log/secure to the CloudWatch agent configuration file on a fleet of EC2 instances so that failed SSH logins can be alarmed. The instance role has the CloudWatchAgentServerPolicy managed policy. The agent is running and still sends /var/log/messages, but no log stream for /var/log/secure appears. What should the engineer do?
- ARun the agent control script with fetch-config to load the updated file
- BAdd the logs:PutRetentionPolicy permission to the instance role
- CRaise the instance metadata hop limit to 2 on the instances
- DReboot the instances so that the agent service starts again with the file
Show the answer and why
ARun the agent control script with fetch-config to load the updated file
Correct
After the configuration file changes, the agent must be started with fetch-config to pick up the new configuration.
BAdd the logs:PutRetentionPolicy permission to the instance role
Incorrect
This permission is needed only if the agent sets retention on its log groups. The managed policy already lets the agent send logs.
CRaise the instance metadata hop limit to 2 on the instances
Incorrect
The hop limit matters when the agent runs in a container and cannot reach instance metadata, which is not the case here.
DReboot the instances so that the agent service starts again with the file
Incorrect
A restart runs the configuration the agent fetched last. The changed file is applied only through fetch-config.
Other logs still arriving rules out permissions and connectivity. What is left is the agent running an old configuration.
AWS documentation