> ## Documentation Index
> Fetch the complete documentation index at: https://docs.aviatrix.com/llms.txt
> Use this file to discover all available pages before exploring further.

# AWS CloudWatch Integration

> If you use CloudWatch, the Aviatrix platform offers a CloudWatch agent for sending syslog from Aviatrix Controller and Aviatrix gateways to your configured AWS CloudWatch instance.

If you use CloudWatch, the Aviatrix platform offers a CloudWatch agent for sending syslog from Aviatrix Controller and Aviatrix gateways to your configured AWS CloudWatch instance.

<Note>
  * Only AWS gateways and Controllers are supported. Other cloud types are not supported.
  * AWS gateways created from an access account with AWS secret key and access key are not supported.
</Note>

## Configuring AWS CloudWatch

In order for Aviatrix Controllers and gateways in different AWS accounts
to send/update logs to the collector's AWS account, follow the
instructions below to set up IAM role and policies on the collector's AWS
account.

1. Go to AWS console, create an IAM role with a name aviatrix-role-cloudwatch.
2. Add Trust-Relationships for Aviatrix Controllers' and all gateways' AWS accounts. If you are already using CloudWatch for logs from all your AWS accounts, you may have already built the trust relationship between accounts. If this is the case, skip this step.
3. Attach AWS IAM Cloudwatch policy to the role aviatrix-role-cloudwatch.

**a: Create an IAM role aviatrix-role-cloudwatch**, make sure the role
name is "aviatrix-role-cloudwatch".

<img src="https://mintcdn.com/aviatrix-14b37c43/Y73dDPMr0NB7yfrH/images/guides/monitoring/create-cloudwatch-role-01.png?fit=max&auto=format&n=Y73dDPMr0NB7yfrH&q=85&s=c041e698a4515eb4a25f213506090b4f" alt="" width="1393" height="739" data-path="images/guides/monitoring/create-cloudwatch-role-01.png" />

<img src="https://mintcdn.com/aviatrix-14b37c43/Y73dDPMr0NB7yfrH/images/guides/monitoring/create-cloudwatch-role-02.png?fit=max&auto=format&n=Y73dDPMr0NB7yfrH&q=85&s=2cff46acc1f0256c43633fe04e0e71f0" alt="" width="1331" height="737" data-path="images/guides/monitoring/create-cloudwatch-role-02.png" />

<img src="https://mintcdn.com/aviatrix-14b37c43/Y73dDPMr0NB7yfrH/images/guides/monitoring/create-cloudwatch-role-03.png?fit=max&auto=format&n=Y73dDPMr0NB7yfrH&q=85&s=3faa7c15a80006c9843f477d2710f5e8" alt="" width="1339" height="795" data-path="images/guides/monitoring/create-cloudwatch-role-03.png" />

<img src="https://mintcdn.com/aviatrix-14b37c43/Y73dDPMr0NB7yfrH/images/guides/monitoring/aviatrix-cloudwatch-iam-role-v2.png?fit=max&auto=format&n=Y73dDPMr0NB7yfrH&q=85&s=6700c32165a820ab78ca7f2d9c332bd2" alt="image1" width="1231" height="611" data-path="images/guides/monitoring/aviatrix-cloudwatch-iam-role-v2.png" />

**b: Add Trust-Relationships for controllers and gateways AWS accounts**

<img src="https://mintcdn.com/aviatrix-14b37c43/Y73dDPMr0NB7yfrH/images/guides/monitoring/adding-trust-relationships-role-v2.png?fit=max&auto=format&n=Y73dDPMr0NB7yfrH&q=85&s=2896cd9941ddd529025d6fefb49073d1" alt="image2" width="1321" height="795" data-path="images/guides/monitoring/adding-trust-relationships-role-v2.png" />

<img src="https://mintcdn.com/aviatrix-14b37c43/B-K895tPeepPiqhY/images/guides/monitoring/trust-relationships-syntax-example-v2.png?fit=max&auto=format&n=B-K895tPeepPiqhY&q=85&s=468ead65336edb2e1eb67569765c76e4" alt="image3" width="1059" height="594" data-path="images/guides/monitoring/trust-relationships-syntax-example-v2.png" />

**c: Attach AWS IAM policy for "CloudWatchAgentServerPolicy" to the role**

<img src="https://mintcdn.com/aviatrix-14b37c43/Y73dDPMr0NB7yfrH/images/guides/monitoring/attach-aws-iam-policy-v2.png?fit=max&auto=format&n=Y73dDPMr0NB7yfrH&q=85&s=8f70e11e4be5127542bd0e71725a3ad9" alt="" width="1316" height="730" data-path="images/guides/monitoring/attach-aws-iam-policy-v2.png" />

**d: Retrieve the ARN of the IAM Role**

<img src="https://mintcdn.com/aviatrix-14b37c43/Y73dDPMr0NB7yfrH/images/guides/monitoring/copy-role-arn.png?fit=max&auto=format&n=Y73dDPMr0NB7yfrH&q=85&s=80b1605070136a73a2e0d83653942975" alt="" width="1316" height="730" data-path="images/guides/monitoring/copy-role-arn.png" />

## Enable CloudWatch log on the Controller

If you are using the Aviatrix Controller user interface, you configure the Aviatrix CloudWatch agent in **Controller > Settings > Logging > CloudWatch Agent**.

<img src="https://mintcdn.com/aviatrix-14b37c43/Y73dDPMr0NB7yfrH/images/guides/monitoring/enable-aviatrix-cloudwatch-v3.png?fit=max&auto=format&n=Y73dDPMr0NB7yfrH&q=85&s=df25d5d427d6e6fad27e4e825eb3bdd4" alt="image5" width="1520" height="829" data-path="images/guides/monitoring/enable-aviatrix-cloudwatch-v3.png" />

<Note>
  * ARN of IAM role: Specify the ARN of the IAM role in the collector's AWS account.
  * Region: Specify which region you wish to store your logs.
</Note>

If you are using the Aviatrix CoPilot user interface, you configure the Aviatrix CloudWatch agent in **CoPilot > Settings > Configuration > Logging Services > CloudWatch Agent**.

## Verifying your AWS CloudWatch integration

In AWS CloudWatch:

<img src="https://mintcdn.com/aviatrix-14b37c43/Y73dDPMr0NB7yfrH/images/guides/monitoring/aws-cloudwatch-result-01.png?fit=max&auto=format&n=Y73dDPMr0NB7yfrH&q=85&s=119c01ef2edc91c2ea9fcf0c7a277a1d" alt="" width="1053" height="628" data-path="images/guides/monitoring/aws-cloudwatch-result-01.png" />

<img src="https://mintcdn.com/aviatrix-14b37c43/Y73dDPMr0NB7yfrH/images/guides/monitoring/aws-cloudwatch-result-02.png?fit=max&auto=format&n=Y73dDPMr0NB7yfrH&q=85&s=1e958bcee3744d789f7c8df5ff7146f1" alt="image7" width="1051" height="642" data-path="images/guides/monitoring/aws-cloudwatch-result-02.png" />

To view the Aviatrix Controller's and Gateways' CloudWatch Service Status:

<img src="https://mintcdn.com/aviatrix-14b37c43/B-K895tPeepPiqhY/images/guides/monitoring/troubleshoot-v2.png?fit=max&auto=format&n=B-K895tPeepPiqhY&q=85&s=c1e3a102891183e8d1bf4520391b2de5" alt="" width="1487" height="640" data-path="images/guides/monitoring/troubleshoot-v2.png" />

<Note>
  Logs from CloudWatch can be exported to S3 buckets. Please follow [AWS Documentation](https://docs.aws.amazon.com/AmazonCloudWatch/latest/logs/S3Export.html).
</Note>
