# AWS CloudWatch

EvoHub receives CloudWatch alarms through an **Amazon SNS topic** with an HTTPS subscription. An alarm that goes to **ALARM** opens an EvoHub alert; the same alarm returning to **OK** resolves it.

## Set it up

:::steps
### Create the integration
In EvoHub, go to **On-Call → Integrations → + Add Integration**, choose **AWS CloudWatch**, pick an **Escalation Policy** and click **Create Integration**. Copy the **Webhook URL**.
### Create the SNS topic
In Amazon SNS, create a **Standard** topic (or use one you have).
### Subscribe EvoHub to the topic
Add a subscription to the topic with **Protocol** `HTTPS` and **Endpoint** your webhook URL. Leave **Raw message delivery** off: EvoHub needs the SNS envelope to check its signature.
### Check the subscription
EvoHub confirms the subscription by itself. In SNS, check that the subscription shows an ARN rather than *PendingConfirmation*.
### Point your alarms at the topic
In each CloudWatch alarm, set the topic as the **In alarm** action **and** the **OK** action. Without the OK action CloudWatch never tells EvoHub the alarm has cleared.
:::

> [!NOTE]
> EvoHub checks the SNS signature on every message against Amazon's signing certificate, so only messages that really come from Amazon SNS are accepted; anything else is refused with `403`. If the certificate cannot be fetched at that moment, EvoHub answers `503` and SNS delivers the message again.

## What EvoHub reads

| EvoHub alert | Taken from |
| --- | --- |
| Title | `AlarmName` (else the SNS subject). |
| Description | `AlarmDescription`, else `NewStateReason`. |
| Labels | `state` — the alarm's new state. |

### Severity

| Alarm state | EvoHub severity |
| --- | --- |
| `ALARM` | critical |
| `INSUFFICIENT_DATA` | low |
| `OK` | resolves the alert |

`INSUFFICIENT_DATA` only reaches EvoHub if you also set the topic as the alarm's **Insufficient data** action; leave that action empty unless a metric that stops reporting should open a low alert.

## Resolve and deduplication

An alert is identified by the AWS account, the region and the alarm name, so identically named alarms in two accounts or regions stay two alerts. While it is open, the alarm firing again is recorded as **Retriggered** instead of paging again; `OK` resolves it. One SNS topic can carry any number of alarms.

## CloudTrail

CloudTrail activity — a root sign-in, logging turned off — pages through this same integration, with a metric filter and an alarm. See [AWS CloudTrail](https://docs-dev.evohub.io/aws-cloudtrail.md).

## Related

- [Integrations overview](https://docs-dev.evohub.io/integrations-overview.md)
- [AWS EventBridge](https://docs-dev.evohub.io/aws-eventbridge.md)
- [AWS CloudTrail](https://docs-dev.evohub.io/aws-cloudtrail.md)
