Skip to content

Triagic + AWS CloudWatch: ticket investigations over your cloud account, read-only

Read CloudWatch logs, metrics, and alarms. Triagic connects to AWS CloudWatch from the desktop app on each member's machine, with a credential you configure, and shows every call it makes while it investigates a ticket. Nothing is copied out of AWS CloudWatch.

What you can ask

  • In AWS CloudWatch, find the log lines for the Lambda that handles webhook retries between 10:00 and 10:20
  • Did the error rate in AWS CloudWatch for the API gateway change in the last six hours?
  • Which alarms in AWS CloudWatch fired this week, and which are still in alarm?
  • Show me the AWS CloudWatch deployment that was live when ticket 4819 was filed
  • What is the dead-letter queue depth in AWS CloudWatch right now?

What the agent can do

These are the 18 tools Triagic exposes from the AWS CloudWatch MCP server. Anything else the server lists is dropped at connect time.

  • describe_log_groups
  • analyze_log_group
  • execute_log_insights_query
  • get_logs_insight_query_results
  • execute_cwl_insights_batch
  • recommend_indexes_loggroup
  • recommend_indexes_account
  • get_metric_data
  • get_metric_metadata
  • analyze_metric
  • get_recommended_metric_alarms
  • execute_promql_query
  • execute_promql_range_query
  • get_promql_label_values
  • get_promql_series
  • get_promql_labels
  • get_active_alarms
  • get_alarm_history

Connect in three steps

  1. 1

    Mint a read-only credential in AWS CloudWatch

    Create a dedicated user or token that can only read. An allowlist of the 18 describe, get and query tools; cancel_logs_insight_query is left out because it changes state.

  2. 2

    Add it in the Triagic portal

    Integrations, then Add shared data source, then AWS CloudWatch.

    • AWS access key ID
    • AWS secret access key
    • Profile name: A profile in the `~/.aws/config` of the machine running Triagic: the name inside `[profile …]`. It is that machine's file, not the portal host's.
    • Region
  3. 3

    Let a desktop pick it up

    Saving validates the shape of what you typed. The first desktop app to sync starts AWS CloudWatch locally and reports running or degraded with the error text.

Field-by-field setup, TLS options and the error table: AWS CloudWatch in the docs.

Read-only, by construction

An allowlist of the 18 describe, get and query tools; cancel_logs_insight_query is left out because it changes state.

FAQ

Can Triagic change anything in AWS CloudWatch?
No. An allowlist of the 18 describe, get and query tools; cancel_logs_insight_query is left out because it changes state. Give it a read-only credential as well, so the guarantee does not rest on one layer.
What do I need to connect AWS CloudWatch?
AWS access key ID, AWS secret access key, Profile name, Region. The desktop app on a member's machine starts the connection; the portal never holds a live process.
Does AWS CloudWatch cost extra?
No. Every connector is included in the seat price. Start a 14-day trial without a card.

Related integrations

Try it on your own AWS CloudWatch

No card. Install the desktop app, connect AWS CloudWatch read-only, and triage a real ticket this afternoon.