AWS Security ChangesHomeSearch

AWS AmazonCloudWatch: CloudWatch agent config docs: fix duplicated text, add apply/update section

Service: AmazonCloudWatch · 2026-09-27 · Documentation low

File: AmazonCloudWatch/latest/monitoring/CloudWatch-Agent-Configuration-File-Details.md

Summary

Removes a duplicated 'of `None` of `None`' phrase from three `unit` option descriptions, adds a TOC entry for 'Update the agent configuration file manually', and adds a new section explaining how the agent applies configuration (amazon-cloudwatch-agent.d fragments, generated amazon-cloudwatch-agent.toml) and warning that starting the agent without an applied configuration can cause the default configuration to replace the active configuration.

Security assessment

The only substantive addition is operational guidance about config-file application and the risk of an unintended default configuration overwriting the active one. This is a configuration-integrity/operations concern, not a specific vulnerability, incident, or security feature; the other edits are cosmetic text fixes.

Evidence

+If this file is absent, starting the agent can apply the default configuration. The default configuration can replace the active configuration in the `amazon-cloudwatch-agent.d` directory. Apply your configuration with `fetch-config` or `append-config` before you start the agent.

Diff

diff --git a/AmazonCloudWatch/latest/monitoring/CloudWatch-Agent-Configuration-File-Details.md b/AmazonCloudWatch/latest/monitoring/CloudWatch-Agent-Configuration-File-Details.md
index 398d9e2fc..c014a6d15 100644
--- a//AmazonCloudWatch/latest/monitoring/CloudWatch-Agent-Configuration-File-Details.md
+++ b//AmazonCloudWatch/latest/monitoring/CloudWatch-Agent-Configuration-File-Details.md
@@ -7 +7 @@
-Save the agent configuration file manuallyUpload the CloudWatch agent configuration file to Systems Manager Parameter Store
+Save the agent configuration file manuallyUpdate the agent configuration file manuallyUpload the CloudWatch agent configuration file to Systems Manager Parameter Store
@@ -250 +250 @@ Within the entry for each individual metric, you might optionally specify one or
-      * `unit` – Specifies the unit to use for this metric, overriding the default unit of `None` of `None` for the metric. The unit that you specify must be a valid CloudWatch metric unit, as listed in the `Unit` description in [MetricDatum](https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_MetricDatum.html).
+      * `unit` – Specifies the unit to use for this metric, overriding the default unit of `None` for the metric. The unit that you specify must be a valid CloudWatch metric unit, as listed in the `Unit` description in [MetricDatum](https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_MetricDatum.html).
@@ -284 +284 @@ Within the entry for each individual metric, you might optionally specify one or
-      * `unit` – Specifies the unit to use for this metric, overriding the default unit of `None` of `None` for the metric. The unit that you specify must be a valid CloudWatch metric unit, as listed in the `Unit` description in [MetricDatum](https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_MetricDatum.html).
+      * `unit` – Specifies the unit to use for this metric, overriding the default unit of `None` for the metric. The unit that you specify must be a valid CloudWatch metric unit, as listed in the `Unit` description in [MetricDatum](https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_MetricDatum.html).
@@ -308 +308 @@ Within the entry for each individual metric, you might optionally specify one or
-      * `unit` – Specifies the unit to use for this metric, overriding the default unit of `None` of `None` for the metric. The unit that you specify must be a valid CloudWatch metric unit, as listed in the `Unit` description in [MetricDatum](https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_MetricDatum.html).
+      * `unit` – Specifies the unit to use for this metric, overriding the default unit of `None` for the metric. The unit that you specify must be a valid CloudWatch metric unit, as listed in the `Unit` description in [MetricDatum](https://docs.aws.amazon.com/AmazonCloudWatch/latest/APIReference/API_MetricDatum.html).
@@ -1699,0 +1700,27 @@ If you create or edit the CloudWatch agent configuration file manually, you can
+## Update the CloudWatch agent configuration file manually
+
+Creating or naming a configuration file does not apply it to the agent. When you apply a configuration, the agent stores it and generates the files that it uses at runtime. On a Linux server, these files are in the `/opt/aws/amazon-cloudwatch-agent/etc` directory, as shown in the following structure.
+    
+    
+    /opt/aws/amazon-cloudwatch-agent/etc/
+        cloudwatch-agent.json         (your source configuration file; you can give it any name)
+        amazon-cloudwatch-agent.d/    (agent-managed directory of active configuration fragments)
+            file_name              (a fragment copied from a local file source)
+            ssm_name               (a fragment copied from a Systems Manager Parameter Store source)
+        amazon-cloudwatch-agent.toml  (generated file that the systemd or upstart service uses to run the agent)
+
+The `amazon-cloudwatch-agent.d` directory holds the active configuration that the agent manages. Keep your source configuration file in a location that you choose, and do not use the `amazon-cloudwatch-agent.d` directory to store source files.
+
+To apply or update the configuration, use the following commands. For the full command syntax and the behavior when configuration file names match, see [Creating multiple CloudWatch agent configuration files](./create-cloudwatch-agent-configuration-file.html#CloudWatch-Agent-multiple-config-files).
+
+  * To apply a source configuration file, run `amazon-cloudwatch-agent-ctl -a fetch-config -c file:`configuration-file-path``. This command applies the initial configuration or replaces the active configuration set.
+
+  * To add another configuration to a running agent without replacing the current one, use the `append-config` option. The `append-config` option preserves the existing configuration fragments, unless a configuration file name matches one that the agent is already using.
+
+
+
+
+###### Note
+
+The systemd and upstart services use the generated `amazon-cloudwatch-agent.toml` file to run the agent. If this file is absent, starting the agent can apply the default configuration. The default configuration can replace the active configuration in the `amazon-cloudwatch-agent.d` directory. Apply your configuration with `fetch-config` or `append-config` before you start the agent.
+