Skip to main content

Amazon Elastic Container Service (ECS) using Container Insights and CloudWatch

ECS icon

Amazon Elastic Container Service (Amazon ECS) is a container management service that lets you run Docker containers on a cluster of Amazon EC2 instances. The Sumo Logic app for Amazon ECS provides preconfigured searches and Dashboards that allow you to monitor various metrics (CPU and Memory Utilization, CPU and Memory Reservation) across ECS clusters and services. The app also monitors API calls made by or on behalf of Amazon ECS in your AWS account.

We offer two different ECS versions, which have separate data collection steps:

This documentation has instructions for collecting logs and metrics for the Amazon ECS app with Container Insights and CloudWatch.

Log and metric types

The Sumo Logic app for Amazon ECS with Container Insights and CloudWatch uses the following logs and metrics:

  • Amazon CloudWatch Metrics
  • Container Insights Metrics
  • Amazon CloudTrail Logs
  • Container Insights Performance Log Events
  • ECS Application Logs
  • Traces

Sample log messages

Click to expand
{
"eventVersion":"1.04",
"userIdentity":{
"type":"AssumedRole",
"principalId":"ADFDDDFF7FDF7GFFF2DF0:i-76vfa923",
"arn":"arn:aws:sts::435456556566:assumed-role/ecsInstanceRole/i-76vfa923",
"accountId":"435456556566",
"accessKeyId":"AOFGPJFIJFFOIJFIOJHF",
"sessionContext":{
"attributes":{
"mfaAuthenticated":"false",
"creationDate":"2017-10-02T20:08:54.107Z"
},
"sessionIssuer":{
"type":"Role",
"principalId":"ADFDDDFF7FDF7GFFF2DF0",
"arn":"arn:aws:iam::435456556566:role/ecsInstanceRole",
"accountId":"435456556566",
"userName":"kevin"
}
}
},
"eventTime":"2017-10-02T20:08:54.107Z",
"eventSource":"ecs.amazonaws.com",
"eventName":"RegisterTaskDefinition",
"awsRegion":"us-west-1",
"sourceIPAddress":"73.168.34.72",
"userAgent":"Amazon ECS Agent - v1.12.2 (ecda8a6) (+http://aws.amazon.com/ecs/)",
"requestParameters":{
"attributes":[
{
"name":"com.amazonaws.ecs.capability.privileged-container"
},
{
"name":"com.amazonaws.ecs.capability.docker-remote-api.1.17"
},
{
"name":"com.amazonaws.ecs.capability.docker-remote-api.1.18"
},
{
"name":"com.amazonaws.ecs.capability.docker-remote-api.1.19"
},
{
"name":"com.amazonaws.ecs.capability.docker-remote-api.1.20"
},
{
"name":"com.amazonaws.ecs.capability.docker-remote-api.1.21"
},
{
"name":"com.amazonaws.ecs.capability.docker-remote-api.1.22"
},
{
"name":"com.amazonaws.ecs.capability.logging-driver.json-file"
},
{
"name":"com.amazonaws.ecs.capability.logging-driver.syslog"
},
{
"name":"com.amazonaws.ecs.capability.logging-driver.awslogs"
},
{
"name":"com.amazonaws.ecs.capability.ecr-auth"
},
{
"name":"com.amazonaws.ecs.capability.task-iam-role"
},
{
"name":"com.amazonaws.ecs.capability.task-iam-role-network-host"
}
],
"totalResources":[
{
"type":"INTEGER",
"doubleValue":0.0,
"integerValue":1024,
"longValue":0,
"name":"CPU"
},
{
"type":"INTEGER",
"doubleValue":0.0,
"integerValue":995,
"longValue":0,
"name":"MEMORY"
},
{
"type":"STRINGSET",
"stringSetValue":[
"22",
"2375",
"2376",
"51678",
"51679"
],
"doubleValue":0.0,
"integerValue":0,
"longValue":0,
"name":"PORTS"
},
{
"type":"STRINGSET",
"stringSetValue":[

],
"doubleValue":0.0,
"integerValue":0,
"longValue":0,
"name":"PORTS_UDP"
}
],
"instanceIdentityDocumentSignature":"pqWe1trtreertermhC6vz\nZ0e/ZyOVVKXOb0fiiouyuyturtyreuFaoghqQ0wWurXzcHb6CrtreyteV6hPM=",
"cluster":"graphite",
"instanceIdentityDocument":"{\n \"privateIp\" : \"10.0.1.83\",\n \"devpayProductCodes\" : null,\n \"availabilityZone\" : \"us-west-1c\",\n \"accountId\" : \"435456556566\",\n \"version\" : \"2010-08-31\",\n \"instanceId\" : \"i-76vfa923\",\n \"billingProducts\" : null,\n \"instanceType\" : \"t2.micro\",\n \"imageId\" : \"ami-444d0224\",\n \"pendingTime\" : \"2016-11-15T21:07:08Z\",\n \"architecture\" : \"x86_64\",\n \"kernelId\" : null,\n \"ramdiskId\" : null,\n \"region\" : \"us-west-1\"\n}"
},
"responseElements":{
"containerInstance":{
"versionInfo":{

},
"runningTasksCount":0,
"ec2InstanceId":"i-13dcar4566",
"remainingResources":[
{
"type":"INTEGER",
"doubleValue":0.0,
"integerValue":1024,
"longValue":0,
"name":"CPU"
},
{
"type":"INTEGER",
"doubleValue":0.0,
"integerValue":995,
"longValue":0,
"name":"MEMORY"
},
{
"type":"STRINGSET",
"stringSetValue":[
"22",
"2376",
"2375",
"51678",
"51679"
],
"doubleValue":0.0,
"integerValue":0,
"longValue":0,
"name":"PORTS"
},
{
"type":"STRINGSET",
"stringSetValue":[

],
"doubleValue":0.0,
"integerValue":0,
"longValue":0,
"name":"PORTS_UDP"
}
],
"agentConnected":true,
"pendingTasksCount":0,
"registeredResources":[
{
"type":"INTEGER",
"doubleValue":0.0,
"integerValue":1024,
"longValue":0,
"name":"CPU"
},
{
"type":"INTEGER",
"doubleValue":0.0,
"integerValue":995,
"longValue":0,
"name":"MEMORY"
},
{
"type":"STRINGSET",
"stringSetValue":[
"22",
"2376",
"2375",
"51678",
"51679"
],
"doubleValue":0.0,
"integerValue":0,
"longValue":0,
"name":"PORTS"
},
{
"type":"STRINGSET",
"stringSetValue":[

],
"doubleValue":0.0,
"integerValue":0,
"longValue":0,
"name":"PORTS_UDP"
}
],
"containerInstanceArn":"arn:aws:ecs:us-west-1:435456556566:container-instance/3f28c319-u9n2-1476-3d2n-b7c254fv411",
"attributes":[
{
"name":"com.amazonaws.ecs.capability.privileged-container"
},
{
"name":"com.amazonaws.ecs.capability.docker-remote-api.1.17"
},
{
"name":"com.amazonaws.ecs.capability.docker-remote-api.1.18"
},
{
"name":"com.amazonaws.ecs.capability.docker-remote-api.1.19"
},
{
"name":"com.amazonaws.ecs.capability.docker-remote-api.1.20"
},
{
"name":"com.amazonaws.ecs.capability.docker-remote-api.1.21"
},
{
"name":"com.amazonaws.ecs.capability.docker-remote-api.1.22"
},
{
"name":"com.amazonaws.ecs.capability.logging-driver.json-file"
},
{
"name":"com.amazonaws.ecs.capability.logging-driver.syslog"
},
{
"name":"com.amazonaws.ecs.capability.logging-driver.awslogs"
},
{
"name":"com.amazonaws.ecs.capability.ecr-auth"
},
{
"name":"com.amazonaws.ecs.capability.task-iam-role"
},
{
"name":"com.amazonaws.ecs.capability.task-iam-role-network-host"
}
],
"status":"ACTIVE",
"version":1
}
},
"requestID":"ae86b372-ab77-11e6-824c-c7c4220f0423",
"eventID":"ff9fc985-1fbe-4717-965b-607dda32f620",
"eventType":"AwsApiCall",
"recipientAccountId":"435456556566"
}

Sample queries

Deleted Resources Over Time
=ecs* (DeleteCluster or DeleteService or DeregisterContainerInstance or DeregisterTaskDefinition or StopTask) and !(InternalFailure)
| json "eventName" as event_name
| parse "\"userName\":\"*\"" as user
| parse "\"awsRegion\":\"*\"" as region
| parse "\"cluster\":\"*\"" as cluster
| timeslice 1h
| parse regex field=event_name "^(?:Delete|Deregister|Stop)(?<resource_type>[A-Z][A-Za-z]+)"
| count by resource_type, _timeslice
| transpose row _timeslice column resource_type

Collecting logs and metrics for Amazon ECS

Configure Hosted Collector

When you create an AWS Source, you'll need to identify the Hosted Collector you want to use or create a new Hosted Collector. Once you create an AWS Source, associate it with a Hosted Collector. For instructions, see Configure a Hosted Collector and Source.

Collect Amazon ECS CloudWatch metrics

Sumo Logic supports collecting metrics using one of the following source types:

  • This app uses aws/ecs and ecs/containerinstance namespaces. Configure an AWS Kinesis Firehose for Metrics Source to collect metrics for both namespaces.

    note

    Namespace for Amazon ECS service is AWS/ECS.
    Namespace for Amazon ECS with container instance metrics is ECS/containerinstance.

Follow the steps below to add custom metadata fields with your metrics:

  1. Click +Add Field under Metadata. Each field consists of a name (key) and a corresponding value.
  2. Create a field named account and assign it a value that represents a friendly name or alias for your AWS account from which metrics are collected. This value will appear in the AWS Observability view, and metrics can be queried using the account field.
    Metadata
  3. After adding fields, check their status indicators:
    • Green check circle A green check mark indicates the field exists and is enabled in the Fields table schema.
    • Orange exclamation point An orange exclamation icon indicates the field does not exist or is disabled in the schema.
      • You will have the option to automatically add or enable the field.
      • If a field is sent but not present or enabled in the schema, it is ignored and marked as Dropped.

Collect Amazon ECS Container Insights metrics

When you enable Container Insights, CloudWatch collects additional metrics in the ECS/ContainerInsights namespace that describe the status of your ECS tasks, resource usage metrics, and the number of running services, containers, and deployments.

In this step, you'll enable Container Insights and set up a collection to ingest those metrics.

  1. Enable Container Insights by referring to the AWS docs using the CLI or AWS console.
  2. If CloudWatch source is selected for collecting metrics, update the source created in the "Collect Amazon ECS CloudWatch metrics" section to include ECS/ContainerInsights in the custom namespaces field; or
    ECS/ContainerInsights
  3. If the Kinesis Firehose source is selected for collecting metrics, update the Metrics Stream to include ECS/ContainerInsights in the custom namespaces field.

Collect Amazon ECS CloudTrail logs

  1. Grant Sumo Logic access to an Amazon S3 bucket.

  2. Create a trail for your AWS account.

  3. Confirm that logs are being delivered to the Amazon S3 bucket.

    note

    Namespace for Amazon ECS service is AWS/ECS.

Follow the steps below to collect logs for Amazon ECS:

  1. Configure a CloudTrail Logs Source.
  2. Add custom metadata fields with your logs:
    1. Click +Add Field under Metadata. Each field consists of a name (key) and a corresponding value.
    2. Create a field named account and assign it a value that represents a friendly name or alias for your AWS account from which logs are collected. This value will appear in the AWS Observability view, and logs can be queried using the account field.
      Metadata
    3. After adding fields, check their status indicators:
      • Green check circle A green check mark indicates the field exists and is enabled in the Fields table schema.
      • Orange exclamation point An orange exclamation icon indicates the field does not exist or is disabled in the schema.
        • You will have the option to automatically add or enable the field.
        • If a field is sent but not present or enabled in the schema, it is ignored and marked as Dropped.

Centralized AWS CloudTrail log collection

In case you have a centralized collection of CloudTrail logs and are ingesting them from all accounts into a single Sumo Logic CloudTrail log source, create the following Field Extraction Rule to map proper AWS account(s) friendly name/alias. Create it if not already present / update it as required.

Rule Name: AWS Accounts
Applied at: Ingest Time
Scope (Specific Data):
_sourceCategory=aws/observability/cloudtrail/logs

Parse Expression

Enter a parse expression to create an "account" field that maps to the alias you set for each sub-account. For example, if you used the "dev" alias for an AWS account with ID "528560886094" and the "prod" alias for an AWS account with ID "567680881046", your parse expression would look like this:

| json "recipientAccountId"
// Manually map your AWS account ID with the AWS account alias you set up earlier for the individual child account
| "" as account
| if (recipientAccountId = "528560886094", "dev", account) as account
| if (recipientAccountId = "567680881046", "prod", account) as account
| fields account

Collect Container Insights performance log events

Container Insights collects data as performance log events using embedded metric format. More details here.

In this step, you'll create a source to collect Task- and Container-level performance events that are not converted into CloudWatch metrics.

  1. Configure an AWS Kinesis Firehose for Logs Source. Add the fields account, region, and namespace as shown below.
    ECS
  2. Copy the KinesisLogsRoleARN and KinesisLogsDeliveryStreamARN values from the Outputs tab of CloudFormation.
    ECS
  3. Go to your CloudWatch > Log Groups and click on your CloudWatch log group /aws/ecs/containerinsights/<cluster>/performance.
    ECS
  4. Click Create, and fill in the parameters below:
    1. Get the delivery stream name from the ARN copied in step 2 and fill in the KinesisLogsDeliverStream field.
    2. Get the role name from the ARN copied in step 2 and fill in the role.
    3. Specify the filter pattern { $.Type = "Container" || $.Type = "Task" }.
    4. Specify the filter name.
    5. Test the pattern and click Start streaming.
      ECS

Collect Amazon ECS application logs

Set up the Container logs collection using the steps in the following docs. You can use the AWS FireLens driver and avoid sending logs to CloudWatch log groups. Also add the account, region, and namespace fields when configuring the source.

If your logs are already sent to CloudWatch log groups, you can create a subscription filter to route the log groups to the delivery stream created in the previous step.

note

Application logs do not contain regions. You have to configure a new Sumo Logic source for each region to avoid creating multiple sources. Then, you will need to add the X-SUMO-Fields header to logConfiguration by creating a custom Fluent Bit image and specifying a custom Fluent Bit configuration.

For more information, see Create a custom Fluent Bit image.

Collect Amazon ECS traces

To set up a collection for traces:

  1. Create an HTTP Traces source by referring to the docs.
  2. Install OpenTelemetry Collector by referring to the docs.

Installing the Amazon ECS app

Now that you have set up collection for Amazon ECS with Container Insights and CloudWatch, install the Sumo Logic app for Amazon ECS to use the preconfigured searches and dashboards that provide visibility into your environment and enable real-time analysis of overall usage.

To install the app, do the following:

note

Next-Gen App: To install or update the app, you must be an account administrator or a user with Manage Apps, Manage Monitors, Manage Fields, Manage Metric Rules, and Manage Collectors capabilities depending upon the different content types part of the app.

  1. Select App Catalog.
  2. In the 🔎 Search Apps field, run a search for your desired app, then select it.
  3. Click Install App.
    note

    Sometimes this button says Add Integration.

  4. Click Next in the Setup Data section.
  5. In the Configure section of your respective app, complete the following fields.
    1. Field Name. If you already have collectors and sources set up, select the configured metadata field name (eg _sourcecategory) or specify other custom metadata (eg: _collector) along with its metadata Field Value.
  6. Click Next. You will be redirected to the Preview & Done section.

Post-installation

Once your app is installed, it will appear in your Installed Apps folder, and dashboard panels will start to fill automatically.

Each panel slowly fills with data matching the time range query received since the panel was created. Results will not immediately be available but will be updated with full graphs and charts over time.

As part of the app installation process, the following content will be created by default along with dashboards and monitor template:

Fields

  • account Name/alias to the AWS account.
  • accountid AWS account ID.
  • region The region to which the resource name belongs.
  • namespace Namespace for Amazon ECS Service is AWS/ECS.
  • clustername The name of the ECS cluster.

Field Extraction Rule(s)

The FER AwsObservabilityECSCloudTrailLogsFER to extract fields region, namespace, clustername, and accountid will be created as part of app installation.

The FER AwsObservabilityECSPerformanceEventsFER, which extracts fields from Container Insights Performance Event Logs for Tasks and Containers, will be created as part of app installation.

note

As a best practice, do not delete or modify any fields, Field Extraction Rules (FERs), or Metric Rules created during the app installation. If you need to make updates, contact the Sumo Logic Support team.

Viewing the Amazon ECS app dashboards

All dashboards have a set of filters that you can apply to the entire dashboard. Use these filters to drill down and examine the data to a granular level.

  • You can change the time range for a dashboard or panel by selecting a predefined interval from a drop-down list, choosing a recently used time range, or specifying custom dates and times. Learn more.
  • You can use template variables to drill down and examine the data on a granular level. For more information, see Filtering Dashboards with Template Variables.
  • Most Next-Gen apps allow you to provide the scope at the installation time and are comprised of a key (_sourceCategory by default) and a default value for this key. Based on your input, the app dashboards will be parameterized with a dashboard variable, allowing you to change the dataset queried by all panels. This eliminates the need to create multiple copies of the same dashboard with different queries.

Cluster Overview

The Amazon ECS - Cluster Overview dashboard provides an overview of CPU and memory utilization, CPU and memory reservation percentages, network I/O (incoming and outgoing bytes), storage read/write activity, the number of EC2 instances registered, and task and service counts across all ECS clusters.

Use this dashboard to:

  • Identify resource-intensive clusters and make informed decisions about your ECS deployment.
  • Monitor CPU and memory utilization and reservation percentages across clusters.
  • View network I/O, storage read/write activity, and registered EC2 instances.
Amazon ECS - Cluster Overview

Container Insights Cluster Overview

The Amazon ECS - Container Insights Cluster Overview dashboard provides Container Insights metrics for ECS clusters, including task, service, EC2 instance counts, network I/O (incoming and outgoing bytes), and storage read/write activity.

Use this dashboard to:

  • Monitor cluster-level operational metrics collected via the Container Insights agent.
  • Track task, service, and EC2 instance counts across clusters.
  • View network throughput and storage activity at the cluster level.
Amazon ECS - Container Insights Cluster Overview

Cluster Resource Reservation

The Amazon ECS - Cluster Resource Reservation dashboard provides detailed insights into the average utilization of CPU, memory, and GPU reservations for a given ECS cluster.

Use this dashboard to:

  • Track resource reservation trends and ensure clusters are appropriately provisioned.
  • Identify potential resource constraints or overprovisioning in your ECS environment.
  • Compare reservation patterns between different types of resources (CPU, memory, GPU) over time.
Amazon ECS - Cluster Resource Reservation

Service Overview

The Amazon ECS - Service Overview dashboard provides an overview of ECS service-level standard CloudWatch metrics, including total service count, average CPU and memory utilization percentages, and CPU/memory utilization trends by service.

Use this dashboard to:

  • Monitor service-level performance and identify services with high resource usage.
  • Track CPU and memory utilization trends across all services.
  • Quickly determine which services require scaling or optimization.
Amazon ECS - Service Overview

Container Insights Service Overview

The Amazon ECS - Container Insights Service Overview dashboard provides Container Insights metrics for ECS services, including running, desired and pending task counts, deployments, task sets, network I/O (incoming and outgoing bytes), and storage read/write activity.

Use this dashboard to:

  • Monitor service-level operational metrics collected via the Container Insights agent.
  • Track running, pending, and desired task counts for each service.
  • View network throughput, storage activity, and deployment status at the service level.
Amazon ECS - Container Insights Service Overview

Tasks Definition Family Overview

The Amazon ECS - Tasks Definition Family Overview dashboard provides an overview of ECS task definition families, including the total family count, task counts by family, CPU and memory utilization, and storage read/write activity.

Use this dashboard to:

  • Monitor resource usage and task distribution across your ECS task definition families.
  • View the number of tasks running with a single task definition family.
  • Track CPU and memory utilization by task definition family.
Amazon ECS - Tasks Definition Family Overview

Tasks Definition Family Performance Monitoring

The Amazon ECS - Tasks Definition Family Performance Monitoring dashboard provides trends around CPU and memory utilization, network I/O (incoming and outgoing bytes), and storage read/write activity for ECS task definition families.

Use this dashboard to:

  • Monitor performance over time and identify resource bottlenecks at the task definition family level.
  • Identify patterns and outliers over time for each of the resource metrics like CPU, memory, network, and disk.
Amazon ECS - Tasks Definition Family Performance Monitoring

Task Definition Family Resource Reservation

The Amazon ECS - Task Definition Family Resource Reservation dashboard provides detailed insights into the average CPU and memory reservation utilization across ECS task definition families.

Use this dashboard to:

  • Track resource reservation trends and ensure task definitions are appropriately sized.
  • Identify the right limits for CPU and memory reservations at the task definition level.
Amazon ECS - Task Definition Family Resource Reservation

Tasks Overview

The Amazon ECS - Tasks Overview dashboard provides an overview of task-level CPU and memory utilization, network I/O (incoming and outgoing bytes), storage read/write activity, and tasks with dropped packets and network errors.

Use this dashboard to:

  • Monitor individual task health and quickly identify tasks with resource or connectivity issues.
  • View details of all the task instances and their launch type.
  • Track network errors and dropped packets by task.
Amazon ECS - Tasks Overview

Container Overview

The Amazon ECS - Container Overview dashboard provides an overview of container-level CPU and memory utilization, network I/O (incoming and outgoing bytes), storage read/write activity, container status trends, and tasks with dropped packets and network errors.

Use this dashboard to:

  • Monitor container health and identify containers with performance or connectivity issues.
  • Track container status and identify container details like task definition, image, and account.
  • Monitor CPU, memory, disk, and network activity of your containers.
Amazon ECS - Container Overview

Container Logs

The Amazon ECS - Container Logs dashboard provides detailed information on container-level log activity, including error trends by cluster and container, top 10 errors, recent errors, and recent container log events.

Use this dashboard to:

  • Quickly diagnose issues and monitor what is happening inside your containers.
  • View recent logs of your container.
  • Identify common errors and abnormal spikes in errors.
Amazon ECS - Container Logs

EC2 LaunchType

The Amazon ECS - EC2 LaunchType dashboard provides an overview of CPU and memory utilization and reservation percentages, the number of EC2 instances registered, and the counts of tasks and services for ECS workloads running on the EC2 launch type.

Use this dashboard to:

  • Monitor the health and resource usage of your EC2-backed ECS clusters.
  • View CPU and memory utilization and reservation percentages for the EC2 launch type.
  • Track the number of clusters, tasks, and registered EC2 instances.
Amazon ECS - EC2 LaunchType

Fargate LaunchType

The Amazon ECS - Fargate LaunchType dashboard provides an overview of running tasks, services, network throughput (incoming and outgoing bytes per second), and storage read/write activity for ECS workloads running on the Fargate launch type.

Use this dashboard to:

  • Monitor the health and network performance of your Fargate-backed ECS clusters.
  • View the number of running tasks and services with the Fargate launch type.
  • Track network throughput and storage activity for Fargate workloads.
Amazon ECS - Fargate LaunchType

Container Insight Audit Events

The Amazon ECS - Container Insight Audit Events dashboard provides insights into changes in your ECS environment, including the top IAM users and the locations of events. The dashboard also shows the created, updated, and deleted events over time, along with details on the top 10 AWS Identity and Access Management users and the last 20 Container Registration and Deregistration Events.

Use this dashboard to:

  • Quickly identify all changes to your ECS environment.
  • Monitor locations from which changes are being made.
  • Examine details and trends for created, updated, and deleted ECS resources.
  • Investigate specific container registration and deregistration events in different regions and clusters.
Amazon ECS - Container Insight Audit Events

Create monitors for Amazon ECS app

From your App Catalog:

  1. From the Sumo Logic navigation, select App Catalog.
  2. In the Search Apps field, search for and then select your app.
  3. Make sure the app is installed.
  4. Navigate to What's Included tab and scroll down to the Monitors section.
  5. Click Create next to the pre-configured monitors. In the create monitors window, adjust the trigger conditions and notifications settings based on your requirements.
  6. Scroll down to Monitor Details.
  7. Under Location click on New Folder.
    note

    By default, monitor will be saved in the root folder. So to make the maintenance easier, create a new folder in the location of your choice.

  8. Enter Folder Name. Folder Description is optional.
    tip

    Using app version in the folder name will be helpful to determine the versioning for future updates.

  9. Click Create. Once the folder is created, click on Save.

Amazon ECS alerts

NameDescriptionAlert ConditionRecover Condition
Amazon ECS Container Insights - High CPU UtilizationThis alert fires when the average CPU utilization within a 5-minute interval for a service within a cluster is high (>=85%).Count >= 85Count < 85
Amazon ECS Container Insights - High Memory UtilizationThis alert fires when the average memory utilization within a 5-minute interval for a service within a cluster is high (>=85%).Count >= 85Count < 85
Amazon ECS Container Insights - No Running Tasks in ServiceThis alert fires when a service has no running tasks for 5 minutes, indicating the service is unavailable and not serving traffic.Count < 1Count >= 1
Amazon ECS Container Insights - High CPU ReservationThis alert fires when the average CPU reservation within a 5-minute interval for a cluster is high (>=85%), indicating the cluster is running out of capacity to schedule new tasks.Count >= 85Count < 85

Upgrade/Downgrade the Amazon ECS (Container Insights and CloudWatch) app (Optional)

To update the app, do the following:

note

Next-Gen App: To install or update the app, you must be an account administrator or a user with Manage Apps, Manage Monitors, Manage Fields, Manage Metric Rules, and Manage Collectors capabilities depending upon the different content types part of the app.

  1. Select App Catalog.
  2. In the Search Apps field, search for and then select your app.
    Optionally, you can identify apps that can be upgraded in the Upgrade available section.
  3. To upgrade the app, select Upgrade from the Manage dropdown.
    1. If the upgrade does not have any configuration or property changes, you will be redirected to the Preview & Done section.
    2. If the upgrade has any configuration or property changes, you will be redirected to the Setup Data page.
    3. In the Configure section of your respective app, complete the following fields.
      1. Field Name. If you already have collectors and sources set up, select the configured metadata field name (eg _sourcecategory) or specify other custom metadata (eg: _collector) along with its metadata Field Value.
    4. Click Next. You will be redirected to the Preview & Done section.

Post-update

Your upgraded app will be installed in the Installed Apps folder and dashboard panels will start to fill automatically.

note

See our Release Notes changelog for new updates in the app.

To revert the app to a previous version, do the following:

  1. Select App Catalog.
  2. In the Search Apps field, search for and then select your app.
  3. To version down the app, select Revert to < previous version of your app > from the Manage dropdown.

Uninstalling the Amazon ECS (Container Insights and CloudWatch) app (Optional)

To uninstall the app, do the following:

  1. Select App Catalog.
  2. In the 🔎 Search Apps field, run a search for your desired app, then select it.
  3. Click Uninstall.
Status
Legal
Privacy Statement
Terms of Use
CA Privacy Notice

Copyright © 2026 by Sumo Logic, Inc.