Getting Started¶
AI Monitor ingests CloudWatch metrics via Metric Streams, learns normal behavior per metric using statistical baselines, and alerts on deviations automatically. This guide covers the path from deployment to your first detections.
Prerequisites¶
- A running Log Processor stack in the same AWS account and Region. AI Monitor deploys as a guest onto its shared VPC, subnets, and OpenSearch domain, so you need the Log Processor stack name before you deploy.
- An AWS Marketplace subscription to AI Monitor.
- Permission to launch CloudFormation in your account.
Deploy¶
- Subscribe to AI Monitor on AWS Marketplace.
- Launch the CloudFormation stack.
- Provide the required parameters — most importantly your Log Processor stack name and the tier you subscribed to.
- For cross-account monitoring (advanced tier and above), supply the organization ID and/or remote account IDs at deploy time.
Subscribe¶
Open the subscription editor (linked from your deployed application's landing page), browse CloudWatch namespaces, and select the metrics and dimensions you want to monitor. Saving a subscription updates the CloudWatch Metric Stream's include filters so only subscribed namespaces stream — adding the first subscription in a namespace starts streaming; removing the last one stops it.
A single subscription can monitor all matching resources independently by using regex wildcards in dimension values.
Baseline¶
After you subscribe, the detector builds a model per metric over the training period — 7 days on most tiers, 14 days on advanced and above. During this phase, alerts can still fire (a genuine spike should alert immediately), but low-confidence alerts are marked while the baseline is still training. To suppress alerts entirely during initial learning, set the baselineDays field on the subscription.
Detect¶
Once the baseline is ready, deviations trigger alerts that include an anomaly score (0–10) and any correlated metrics. Alerts are delivered via SNS and carry message attributes (severity, score, namespace, metricName, subscriptionId, description, accountId) you can use for filter-based routing to email, webhooks, Slack/Teams, PagerDuty, Lambda, SQS, and more.
Further reading¶
The published product includes additional reference guides distributed as downloads: a Subscription Editor Guide, OpenSearch Guide, User Management Guide, Single Sign-On Integration Guide, and Monitoring Guide.