AWS Security ChangesHomeSearch

AWS AWSEC2: Reorganize EFA metrics monitoring guidance, add CloudWatch agent link

Service: AWSEC2 · 2026-09-27 · Documentation low

File: AWSEC2/latest/UserGuide/efa-working-monitor.md

Summary

Reorders the EFA monitoring section so the CloudWatch agent method is described first, and adds a link to the CloudWatch agent EFA metrics documentation; the EKS Container Insights paragraph is moved below.

Security assessment

The change only reorders monitoring documentation and adds a cross-reference to the CloudWatch agent; it introduces no security controls, credentials, or vulnerability fixes.

Evidence

+To collect EFA driver metrics from an instance and publish them to CloudWatch, you can use the CloudWatch agent. For more information, see [Collect EFA metrics with the CloudWatch agent](https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/CloudWatch-Agent-EFA.html) in the _Amazon CloudWatch User Guide_.

Diff

diff --git a/AWSEC2/latest/UserGuide/efa-working-monitor.md b/AWSEC2/latest/UserGuide/efa-working-monitor.md
index 7b198fcba..0fb990941 100644
--- a//AWSEC2/latest/UserGuide/efa-working-monitor.md
+++ b//AWSEC2/latest/UserGuide/efa-working-monitor.md
@@ -209 +209 @@ In the flow log entries, EFA traffic is identified by the `srcAddress` and `dest
-If you are using EFA in an Amazon EKS cluster, you can monitor your EFAs using CloudWatch Container Insights. Amazon CloudWatch Container Insights supports all of the EFA driver metrics, except: `retrans_bytes`, `retrans_pkts`, `retrans_timeout_events`, `unresponsive_remote_events`, and `impaired_remote_conn_events`.
+To collect EFA driver metrics from an instance and publish them to CloudWatch, you can use the CloudWatch agent. For more information, see [Collect EFA metrics with the CloudWatch agent](https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/CloudWatch-Agent-EFA.html) in the _Amazon CloudWatch User Guide_.
@@ -211 +211 @@ If you are using EFA in an Amazon EKS cluster, you can monitor your EFAs using C
-For more information, see [ Amazon EKS and Kubernetes Container Insights metrics](https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/Container-Insights-metrics-enhanced-EKS.html#Container-Insights-metrics-EFA) in the _Amazon CloudWatch User Guide_.
+If you are using EFA in an Amazon EKS cluster, you can monitor your EFAs using CloudWatch Container Insights. Amazon CloudWatch Container Insights supports all of the EFA driver metrics, except: `retrans_bytes`, `retrans_pkts`, `retrans_timeout_events`, `unresponsive_remote_events`, and `impaired_remote_conn_events`. For more information, see [ Amazon EKS and Kubernetes Container Insights metrics](https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/Container-Insights-metrics-enhanced-EKS.html#Container-Insights-metrics-EFA) in the _Amazon CloudWatch User Guide_.