A company is migrating its on-premises applications to AWS. They have a hybrid environment where some applications will remain on-premises, and others will move to Amazon EC2. The security team requires a centralized logging solution for both on-premises application logs (Apache, Nginx, custom app logs) and EC2 instance logs, with real-time alerting capabilities. The solution must minimize operational overhead. Which approach should the DevOps team take?
- AConfigure AWS CloudTrail to capture API calls from on-premises applications and EC2 instances, sending them to CloudWatch Logs.
- BUse AWS Kinesis Data Firehose to ingest logs from on-premises and EC2 instances, then stream them to Amazon S3 for archival.
- CDeploy the CloudWatch Agent to all on-premises servers and EC2 instances, configuring it to send logs to Amazon CloudWatch Logs.
- DInstall a custom Fluentd agent on all on-premises and EC2 instances to send logs to a self-managed Amazon OpenSearch Service cluster.
Show answer & explanationAnswer & explanation
Correct answer: C. Deploy the CloudWatch Agent to all on-premises servers and EC2 instances, configuring it to send logs to Amazon CloudWatch Logs.
The CloudWatch Agent is specifically designed for collecting logs and metrics from both Amazon EC2 instances and on-premises servers. By deploying and configuring it on all instances, logs from both environments can be centrally sent to Amazon CloudWatch Logs. CloudWatch Logs provides real-time alerting, log analytics (Logs Insights), and minimizes operational overhead by being a fully managed service, directly addressing all requirements.
Why the other options are wrong
- A. AWS CloudTrail captures AWS API calls, not application or system logs from on-premises servers or EC2 instances. It's not suitable for general application log collection.
- B. While Kinesis Data Firehose can ingest logs, streaming directly to S3 primarily serves archival purposes. It lacks the real-time analytics and alerting capabilities of CloudWatch Logs without additional services.
- D. A self-managed OpenSearch Service cluster (even if on AWS) still involves significant operational overhead for cluster management, scaling, and maintenance, which goes against the 'minimize operational overhead' requirement.
CloudWatch Agent for Hybrid Logging
The CloudWatch Agent centralizes log collection from both on-premises servers and Amazon EC2 instances into Amazon CloudWatch Logs for unified monitoring and analysis.
- Single agent for hybrid environments.
- Collects application logs (Apache, Nginx, custom) and system logs.
- Integrates with CloudWatch Logs for analysis, retention, and alerting.
Memory trick: CloudWatch Agent: Your logs' bridge from on-prem to CloudWatch.