Astry offers two integrations with Amazon Web Services. Both rely on Amazon SNS (Simple Notification Service): your services publish messages to an SNS topic in your AWS account, which then forwards them to Astry through an HTTPS subscription.
As with other integrations, they must be enabled by an Owner, from the main Organization tab, then Incoming Integrations.
Amazon CloudWatch
Amazon CloudWatch is the native AWS monitoring service. By integrating it with Astry, you can trigger incidents from CloudWatch alarms (metric thresholds) or CloudWatch logs.
Configuration
- Generate a key from the Amazon CloudWatch integration page, and copy the endpoint URL.
- Create an SNS topic (Standard type) in your AWS account. In the HTTP/S delivery policy, set the Content-Type to
application/json. Then add an HTTPS subscription to the endpoint URL copied in step 1. - Link your alarms to the SNS topic:
- for CloudWatch alarms: add the SNS topic as an action for the In alarm state
- for CloudWatch logs: create a metric filter on a log group, then a CloudWatch alarm based on this metric, linked to the SNS topic
AWS sends a subscription confirmation request to the Astry endpoint: it is handled automatically, and the subscription is active within a few seconds.
Field mapping
When a CloudWatch alarm fires, Astry automatically extracts the following fields:
| Incident field | CloudWatch alarm field |
|---|---|
| Title | AlarmName |
| Description | NewStateReason |
| correlationId (de-duplication) | AlarmArn |
Amazon SNS
The Amazon SNS integration lets you trigger incidents from any message published to an SNS topic: from your applications (through the AWS SDK or CLI), or from any AWS service able to publish to an SNS topic (CloudWatch, Lambda, EventBridge, ...).
Configuration
- Configure the field mapping (see below) and save it.
- Generate a key and copy the endpoint URL.
- Create an SNS topic in your AWS account (Standard type, Content-Type
application/json), with an HTTPS subscription to the endpoint URL. The subscription confirmation is handled automatically here too. - Publish messages to the SNS topic whenever you want to raise an incident.
Field mapping
The title, description, correlationId and priority of the incident can each be defined:
- statically, with a fixed value (for example Message received on the SNS topic)
- or dynamically, from a field of the message, by prefixing it with
$(for example$message,$topicArnor$severity)
A default priority (from Critical to Informational) is used when the priority field is missing from the message. Only Owners can change this configuration.
Keys and rotation
You can have up to 5 keys per integration. To rotate a key without downtime (for example if it was compromised): generate a new key, update the URL of your SNS subscription with this new key, then revoke the old one.