# Triagic + AWS SQS / SNS: ticket investigations over your cloud account, read-only

> AWS SQS / SNS in Triagic: Inspect queues, topics, and message attributes. Read-only, with a credential you configure.

Source: https://triagic.com/integrations/aws-sqs-sns

## What you can ask

- In AWS SQS / SNS, find the log lines for the Lambda that handles webhook retries between 10:00 and 10:20
- Did the error rate in AWS SQS / SNS for the API gateway change in the last six hours?
- Which alarms in AWS SQS / SNS fired this week, and which are still in alarm?
- Show me the AWS SQS / SNS deployment that was live when ticket 4819 was filed
- What is the dead-letter queue depth in AWS SQS / SNS right now?

## What the agent can do

- `check_if_phone_number_is_opted_out`
- `get_data_protection_policy`
- `get_endpoint_attributes`
- `get_platform_application_attributes`
- `get_subscription_attributes`
- `get_topic_attributes`
- `list_endpoints_by_platform_application`
- `list_origination_numbers`
- `list_phone_numbers_opted_out`
- `list_platform_applications`
- `list_subscriptions`
- `list_subscriptions_by_topic`
- `list_tags_for_resource`
- `list_topics`
- `get_queue_attributes`
- `get_queue_url`
- `list_dead_letter_source_queues`
- `list_message_move_tasks`
- `list_queue_tags`
- `list_queues`

## Connect in three steps

1. **Mint a read-only credential in AWS SQS / SNS.** Create a dedicated user or token that can only read. An allowlist of 20 list and get calls; receive_message is excluded because it hides messages from the real consumers.
2. **Add it in the Triagic portal.** Integrations, then Add shared data source, then AWS SQS / SNS. Fill in: AWS access key ID (required); AWS secret access key (required); Profile name (required): A profile in the `~/.aws/config` of the machine running Triagic: the name inside `[profile …]`. It is that machine's file, not the portal host's.; Region (required)
3. **Let a desktop pick it up.** Saving validates the shape of what you typed. The first desktop app to sync starts AWS SQS / SNS locally and reports running or degraded with the error text.

Setup reference: https://triagic.com/docs/integrations/cloud#aws-sqs--sns

## Read-only, by construction

An allowlist of 20 list and get calls; receive_message is excluded because it hides messages from the real consumers.

## FAQ

**Can Triagic change anything in AWS SQS / SNS?**
No. An allowlist of 20 list and get calls; receive_message is excluded because it hides messages from the real consumers. Give it a read-only credential as well, so the guarantee does not rest on one layer.

**What do I need to connect AWS SQS / SNS?**
AWS access key ID, AWS secret access key, Profile name, Region. The desktop app on a member's machine starts the connection; the portal never holds a live process.

**Does AWS SQS / SNS cost extra?**
No. Every connector is included in the seat price. Start a 14-day trial without a card.

## Related integrations

- [AWS CloudWatch](https://triagic.com/integrations/aws-cloudwatch)
- [Azure Monitor](https://triagic.com/integrations/azure-monitor)
- [Azure](https://triagic.com/integrations/azure)
- [Google Cloud Logging](https://triagic.com/integrations/gcp-logging)
