Question 1 · choose 1
A company runs microservices in 50 accounts. During incidents, engineers sign in to several accounts one after another to read metrics, logs and traces, which slows down diagnosis. The company wants one account in which engineers can search and correlate this telemetry from all 50 accounts without copying the data. What should a solutions architect do?
- ACreate CloudWatch dashboards in each of the 50 accounts and share them publicly with the operations team
- BUse CloudWatch cross-account observability with a monitoring account and the 50 accounts linked as sources
- CCreate an organization trail in CloudTrail and search its log files during each incident
- DExport all log groups from the 50 accounts to one S3 bucket every hour and query them with Amazon Athena
Show the answer and why
ACreate CloudWatch dashboards in each of the 50 accounts and share them publicly with the operations team
Incorrect
Sharing dashboards lets people view them, but engineers would still move between 50 separate dashboards and could not query across accounts.
BUse CloudWatch cross-account observability with a monitoring account and the 50 accounts linked as sources
Correct
With cross-account observability, a central monitoring account can view and interact with the metrics, logs and traces generated in the source accounts linked to it, and search across them.
CCreate an organization trail in CloudTrail and search its log files during each incident
Incorrect
CloudTrail records API activity in the accounts. It does not hold application metrics, logs or traces.
DExport all log groups from the 50 accounts to one S3 bucket every hour and query them with Amazon Athena
Incorrect
Exports copy the data and arrive late, they do not include metrics or traces, and they are a poor fit for live incident diagnosis.
"One place, all accounts, no copies" is CloudWatch cross-account observability with one monitoring account.
AWS documentation