Troubleshooting
If these instructions don’t address your issue, Contact AWS Support provides instructions for opening an AWS Support case for this solution.
Problem: Amazon CloudWatch Events bus permissions error
If during spoke stack deployment, you received a CREATE_FAILEDmessage for the TAWarnRule and/or the TASErrorRule, verify that the CloudWatch Event Bus in the primary account allows the spoke account to send events to the primary account.
Resolution
Update the primary stack with the secondary account ID or complete the following task:
-
In the primary account, navigate to the CloudWatch console
. -
In the navigation pane, select Event Buses.
-
Select Add Permissions.
-
For Principal, enter the applicable secondary account ID.
-
Select the Everybody(*) checkbox.
-
Choose Add.