AWS Certified DevOps Engineer – ProfessionalMonitoring and LoggingMedium

A DevOps team requires a comprehensive monitoring solution for their containerized application running on Amazon EKS. They need to collect metrics at the node, pod, and container level, analyze application logs, and visualize the health and performance of their Kubernetes cluster. The solution should be scalable, cost-effective, and provide deep insights into the EKS environment. Which combination of AWS services and open-source tools is most suitable?

  1. AUtilize Amazon CloudWatch Container Insights for metrics and logs, and Amazon Managed Service for Prometheus (AMP) for Prometheus-compatible metrics.
  2. BUse Amazon CloudWatch Logs for all logs, and deploy a self-managed Prometheus and Grafana stack outside the EKS cluster for metrics.
  3. CImplement AWS Distro for OpenTelemetry (ADOT) with Prometheus receiver for metrics and OTLP exporter for logs to CloudWatch Logs.
  4. DDeploy Prometheus and Grafana on an EC2 instance within the EKS cluster for metrics, and use Fluentd to send logs to CloudWatch Logs.
Show answer & explanation

Correct answer: A. Utilize Amazon CloudWatch Container Insights for metrics and logs, and Amazon Managed Service for Prometheus (AMP) for Prometheus-compatible metrics.

Amazon CloudWatch Container Insights is specifically designed for monitoring containerized applications, providing automated collection and aggregation of metrics and logs at the cluster, node, pod, and container levels for EKS. Integrating with Amazon Managed Service for Prometheus (AMP) allows for collecting Prometheus-compatible metrics at scale without managing the Prometheus infrastructure, offering a comprehensive, scalable, and cost-effective solution for EKS monitoring.

Why the other options are wrong

  • B. Deploying self-managed Prometheus/Grafana outside the EKS cluster still involves significant management overhead and might incur higher costs than managed services like AMP, especially for high-scale environments. CloudWatch Logs is good for logs, but the metrics part is not optimal.
  • C. ADOT can be used, but it requires more configuration and setup compared to the more out-of-the-box integration of Container Insights and AMP for a fully managed solution. While powerful, it adds complexity if not strictly needed.
  • D. Deploying self-managed Prometheus/Grafana on EC2 introduces operational overhead. While Fluentd to CloudWatch Logs is good for logs, the metrics solution is not fully managed.

Amazon CloudWatch Container Insights

A feature of Amazon CloudWatch that collects, aggregates, and summarizes metrics and logs from containerized applications and microservices running on Amazon ECS, Amazon EKS, and AWS Fargate.

  • Provides deep visibility into container performance (CPU, memory, network).
  • Automatically collects metrics and logs at various granularities.
  • Includes dashboards and can create alarms.

Memory trick: Container Insights Monitors EKS, AMP Adds Prometheus Power.

More Monitoring and Logging questions