Select your cookie preferences

We use essential cookies and similar tools that are necessary to provide our site and services. We use performance cookies to collect anonymous statistics, so we can understand how customers use our site and make improvements. Essential cookies cannot be deactivated, but you can choose “Customize” or “Decline” to decline performance cookies.

If you agree, AWS and approved third parties will also use cookies to provide useful site features, remember your preferences, and display relevant content, including relevant advertising. To accept or decline all non-essential cookies, choose “Accept” or “Decline.” To make more detailed choices, choose “Customize.”

Monitoring IAM Roles Anywhere with Amazon CloudWatch

Focus mode
Monitoring IAM Roles Anywhere with Amazon CloudWatch - IAM Roles Anywhere

You can monitor AWS Identity and Access Management Roles Anywhere using CloudWatch, which collects raw data and processes it into readable, near real-time metrics. These statistics are kept for 15 months, so that you can access historical information and gain a better perspective on how your web application or service is performing. You can also set alarms that watch for certain thresholds, and send notifications or take actions when those thresholds are met. For more information, see the Amazon CloudWatch User Guide.

For IAM Roles Anywhere, you might want to watch for trust anchor and end-entity certificates expiration dates and renew your certificates when your certificates are nearing expiration.

The IAM Roles Anywhere service reports the following metrics in the AWS/RolesAnywhere namespace.

Metric Description

Success

Gets published every time CreateSession succeeds in returning credentials to the user.

Valid Dimensions: Operation, TrustAnchorArn

Valid Statistic: Sum

Units: Count

Failure

Gets published every time CreateSession fails to return credentials to the user.

Valid Dimensions: Operation, ErrorType

Valid Statistic: Sum

Units: Count

DaysToExpiry

Gets published every time trust anchor certificates satisfies notification evaluation criteria. This metric will be published at most once a day.

Valid Dimensions: TrustAnchorArn

Units: Integer

The following dimensions are supported for the IAM Roles Anywhere metrics.

Dimension Description
Operation

The operation for which the metric applies to. This can only take on the value, CreateSession.

TrustAnchorArn

The ARN of the trust anchor that is relevant for this metric.

ErrorType

The type of error that CreateSession errors out with.

PrivacySite termsCookie preferences
© 2025, Amazon Web Services, Inc. or its affiliates. All rights reserved.