A company operates a critical serverless application composed of AWS Lambda functions, Amazon DynamoDB, and Amazon SQS. They need to monitor the application's health and performance by tracking key metrics such as Lambda invocation errors, DynamoDB throttled requests, and SQS message visibility timeouts. It is crucial to have custom dashboards combining these metrics and to receive alerts when anomalies occur, rather than fixed thresholds. Which solution best meets these requirements?
- AImplement custom metrics publishing to CloudWatch using the Embedded Metric Format (EMF) and then create CloudWatch Alarms with fixed thresholds.
- BUtilize CloudWatch Alarms with anomaly detection enabled for each metric and create custom CloudWatch Dashboards.
- CCreate CloudWatch Alarms for fixed thresholds on each metric and manually combine them into a CloudWatch Dashboard.
- DExport all metrics to Amazon S3, then use Amazon Athena to query and build custom dashboards in QuickSight.
Show answer & explanationAnswer & explanation
Correct answer: B. Utilize CloudWatch Alarms with anomaly detection enabled for each metric and create custom CloudWatch Dashboards.
CloudWatch Alarms with anomaly detection are specifically designed to alert on deviations from expected metric behavior, which is ideal for 'anomalies rather than fixed thresholds'. CloudWatch automatically learns normal patterns and creates a band. Custom CloudWatch Dashboards allow combining metrics from various services (Lambda, DynamoDB, SQS) into a single view, fulfilling all requirements for monitoring and alerting on anomalies.
Why the other options are wrong
- A. EMF is great for custom metrics, but the question specifically asks for 'anomalies rather than fixed thresholds' for alerting, which EMF itself doesn't provide. It would still require CloudWatch Alarms, which should then use anomaly detection, making this option incomplete for the alerting requirement.
- C. Fixed thresholds are explicitly stated as not desired for anomaly detection. While dashboards are met, the alerting mechanism is not optimal.
- D. Exporting to S3 and using Athena/QuickSight provides powerful analytics and dashboards but is not suitable for real-time anomaly-based alerting. It adds latency and complexity for the primary alerting need.
CloudWatch Anomaly Detection
A feature of Amazon CloudWatch that uses machine learning algorithms to continuously analyze past metric data, create a baseline, and identify when a metric's current value falls outside of the expected range.
- Automatically learns normal metric patterns.
- Alerts on deviations from the expected baseline.
- Reduces alert fatigue from static thresholds.
Memory trick: Anomaly Alarms Detect Deviations, Dashboards Display Details.