AWS Key Management Service (AWS KMS) lets you create, manage, and control cryptographic keys across your applications and AWS services.

Cisco Cloud Observability only monitors KMS keys with key material origin values of AWS_KMS and EXTERNAL(Import key material). KMS keys that originate from an AWS CloudHSM or external key store are not monitored.

You must configure cloud connections to monitor this entity. See Set up Cisco AppDynamics Cloud Collectors to Monitor AWS.

Cisco Cloud Observability displays AWS entities on the Observe page. Metrics are displayed for specific entity instances in the list and detail views.

This document contains references to third-party documentation. Splunk AppDynamics does not own any rights and assumes no responsibility for the accuracy or completeness of such third-party documentation.

List View

To display the list view for an AWS KMS key:

  1. Navigate to the Observe page. 
  2. Under Cloud Governance & Security Management, click AWS KMS Keys.
    The list view now displays a list of all of your KMS keys and a subset of their properties.
  3. From the list, click a row to display the tags and full list of properties for the KMS key.

Metrics and Key Performance Indicators

Cisco Cloud Observability displays the following metrics and key performance indicators (KPIs) for AWS KMS keys. For more information, see Monitoring with Amazon CloudWatch.

Display NameSource Metric NameDescription
Key Material Expiration SecondsSecondsUntilKeyMaterialExpirationThe number of seconds remaining until the imported key material in a KMS key expires. This metric is valid only for KMS keys with imported key material (a key material origin of EXTERNAL) and an expiration date.

Properties (Attributes)

Cisco Cloud Observability displays the following properties for AWS KMS keys.

Display NameProperty NameDescription
Arnaws.kms_key.arnThe Amazon Resource Name (ARN) of the KMS key.
Key Idcloud.managed_key.key_idThe unique identifier of the KMS key.
Creation Dateaws.kms_key.creation_dateThe date and time when the KMS key was created.
Enabledaws.kms_key.enabledSpecifies whether the KMS key is enabled.
Descriptionaws.kms_key.descriptionThe description of the KMS key.
Key Usageaws.kms_key.key_usageThe cryptographic operations for which you can use the KMS key.

Key State

aws.kms_key.key_stateThe current status of the KMS key.
Deletion Dateaws.kms_key.deletion_dateThe date and time after which KMS deletes this KMS key. This value is present only when the KMS key is scheduled for deletion (when its KeyState is PendingDeletion).

Origin

aws.kms_key.originThe source of the key material for the KMS key. When this value is AWS_KMS, KMS created the key material. When this value is EXTERNAL, the key material was imported or the KMS key doesn't have any key material.

Expiration Model

aws.kms_key.expiration_modelSpecifies whether the KMS key's key material expires. This value is present only when Origin is EXTERNAL; otherwise, this value is omitted.

Valid To

aws.kms_key.valid_toThe time at which the imported key material expires.

Key Manager

aws.kms_key.key_managerThe manager of the KMS key. KMS keys in your Amazon Web Services account are either customer managed or Amazon Web Services managed.

Key Spec

aws.kms_key.key_specThe manager of the KMS key. KMS keys in your Amazon Web Services account are either customer managed or Amazon Web Services managed.

Multi Region

aws.kms_key.multi_regionIndicates whether the KMS key is a multi-Region (True) or regional (False) key.

Pending Deletion Window In Days

aws.kms_key.pending_deletion_window_in_daysIndicates whether the KMS key is a multi-Region (True) or regional (False) key.

Account Id

cloud.account.idThe cloud account ID the resource is assigned to.

Region

cloud.regionThe geographical region in which the resource resides.

Retention and Purge Time-To-Live (TTL)

For all cloud and infrastructure entities, the retention TTL is 180 minutes (3 hours) and the purge TTL is 525,600 minutes (365 days). 

Amazon Web Services, the AWS logo, AWS, and any other AWS Marks used in these materials are trademarks of Amazon.com, Inc. or its affiliates in the United States and/or other countries.