Network Performance Monitoring is now generally available! Network Monitoring is now available!

Amazon Key Management Service

Crawler Crawler

Overview

AWS Key Management Service (KMS) is a managed service that makes it easy for you to create and control the encryption keys used to encrypt your data.

Enable this integration to see in Datadog all your KMS metrics.

Setup

Installation

If you haven’t already, set up the Amazon Web Services integration first.

Metric collection

  1. In the AWS integration tile, ensure that KMS is checked under metric collection.

  2. Install the Datadog - AWS KMS integration.

Log collection

Enable logging

Configure Amazon KMS to send logs either to a S3 bucket or to Cloudwatch.

Note: If you log to a S3 bucket, make sure that amazon_kms is set as Target prefix.

Send logs to Datadog

  1. If you haven’t already, set up the Datadog log collection AWS Lambda function.
  2. Once the lambda function is installed, manually add a trigger on the S3 bucket or Cloudwatch log group that contains your Amazon KMS logs in the AWS console:

Data Collected

Metrics

aws.kms.seconds_until_key_material_expiration
(gauge)
This metric tracks the number of seconds remaining until imported key material expires.
Shown as second

Each of the metrics retrieved from AWS will be assigned the same tags that appear in the AWS console, including but not limited to host name, security-groups, and more.

Events

The AWS KMS integration does not include any events.

Service Checks

The AWS KMS integration does not include any service checks.

Troubleshooting

Need help? Contact Datadog support.