AWS Certificate Manager (ACM) handles the complexity of creating, storing, and renewing public and private SSL/TLS X.509 certificates and keys that protect your AWS websites and applications.

You must configure cloud connections to monitor this entity. See Set up Cisco AppDynamics Cloud Collectors to Monitor AWS.

Cisco Cloud Observability displays AWS entities on the Observe page. Metrics are displayed for specific entity instances in the list and detail views.

This document contains references to third-party documentation. Splunk AppDynamics does not own any rights and assumes no responsibility for the accuracy or completeness of such third-party documentation.

List View

To display the list view for an ACM certificate:

  1. Navigate to the Observe page. 
  2. Under Cloud Governance & Security Management, click AWS ACM Certificates.
    The list view now displays.
  3. From the list, you can:
    1. View the Domain Name and Days to Expiry.
    2. Click the row for an ACM certificate to display the Properties panel on the right.

Metrics and Key Performance Indicators

Cisco Cloud Observability displays the following metrics and key performance indicators (KPIs) for ACM certificates. For more information, see Supported CloudWatch metrics.

Display NameSource Metric NameDescription
DaysToExpiry (Count)DaysToExpiryNumber of days until a certificate expires. ACM stops publishing this metric after a certificate expires.

Properties (Attributes)

Cisco Cloud Observability displays the following properties for ACM certificates.

Display NameProperty NameDescription
Certificate Arnaws.acm_certificate.arnThe Amazon Resource Name (ARN) of the ACM Certificate.
Certificate Domain Nameaws.acm_certificate.domain_nameThe fully qualified domain name (FQDN) of the domain on which to perform validation.
Certificate Statusaws.acm_certificate.status

The status of the certificate:

  • PENDING_VALIDATION
  • ISSUED
  • INACTIVE
  • EXPIRED
  • VALIDATION_TIMED_OUT
  • REVOKED
  • FAILED
Certificate Creation Timeaws.acm_certificate.created_atThe time at which the certificate was requested.
Certificate Import Timeaws.acm_certificate.imported_atThe date and time at which the certificate was imported. This value exists only when the certificate type is IMPORTED.
Certificate Issue Timeaws.acm_certificate.issued_atThe time at which the certificate was issued. This value exists only when the certificate type is AMAZON_ISSUED.
Certificate Revocation Timeaws.acm_certificate.revoked_atThe time at which the certificate was revoked. This value exists only when the certificate status is REVOKED.
Certificate Revocation Reasonaws.acm_certificate.revoke_reasonThe reason the certificate was revoked. This value exists only when the certificate status is REVOKED.
Certificate Key Algorithmaws.acm_certificate.key_algorithmThe algorithm that was used to generate the public-private key pair.
Certificate Signature Algorithmaws.acm_certificate.signature_algorithmThe algorithm that was used to sign the certificate.
Certificate Failure Reasonaws.acm_certificate.failure_reasonThe reason the certificate request failed. This value exists only when the certificate status is FAILED.
Certificate Sourceaws.acm_certificate.sourceThe source of the certificate. For certificates provided by ACM, this value is AMAZON_ISSUED.
Certificate Renewal Eligibilityaws.acm_certificate.renewal_eligibilitySpecifies whether the certificate is eligible for renewal. At this time, only exported private certificates can be renewed with the RenewCertificate command.

Retention and Purge Time-To-Live (TTL)

For all cloud and infrastructure entities, the retention TTL is 180 minutes (3 hours) and the purge TTL is 525,600 minutes (365 days). 

Amazon Web Services, the AWS logo, AWS, and any other AWS Marks used in these materials are trademarks of Amazon.com, Inc. or its affiliates in the United States and/or other countries.