<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dynatrace set up on AWS in Cloud platforms</title>
    <link>https://community.dynatrace.com/t5/Cloud-platforms/Dynatrace-set-up-on-AWS/m-p/224326#M1351</link>
    <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/22988"&gt;@agrawal_shashan&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Is it possible that the ActiveGate you're set up is not correctly linked to your tenant, as in, there is no communication to it somehow? Does it appear if you search for it under Deployment Status -&amp;gt; ActiveGates? And does it have the AWS module enabled?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="victor_balbuena_0-1696232992917.png" style="width: 400px;"&gt;&lt;img src="https://community.dynatrace.com/t5/image/serverpage/image-id/14393i1DA936E94D1201E9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="victor_balbuena_0-1696232992917.png" alt="victor_balbuena_0-1696232992917.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;For your second question, it is the ActiveGate itself that connects to your AWS account, polls the metrics from AWS Cloudwatch and then sends them to the Dynatrace cluster - everything happens in the ActiveGate.&lt;/P&gt;</description>
    <pubDate>Mon, 02 Oct 2023 08:39:23 GMT</pubDate>
    <dc:creator>victor_balbuena</dc:creator>
    <dc:date>2023-10-02T08:39:23Z</dc:date>
    <item>
      <title>Dynatrace set up on AWS</title>
      <link>https://community.dynatrace.com/t5/Cloud-platforms/Dynatrace-set-up-on-AWS/m-p/224306#M1349</link>
      <description>&lt;P&gt;Hello, I am trying to set up Dynatrace to monitor resources in AWS. We use Dynatrace Managed which is hosted on our on-prem infrastructure so following this &lt;A href="https://www.dynatrace.com/support/help/shortlink/aws-managed-deployment" target="_self"&gt;documentation&lt;/A&gt;, we have set up an Environment Active gate on EC2 instance.&lt;/P&gt;&lt;P&gt;I have completed all the steps listed, created an IAM role and attached to the EC2 instance where my Environment Active gate is deployed. Now while doing the last step which is listed &lt;A href="https://www.dynatrace.com/support/help/shortlink/aws-managed-deployment#connect-your-amazon-account" target="_self"&gt;here&lt;/A&gt; when I make the connection to AWS from Dynatrace UI, I am getting an error message which says &lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;"Active gate unavailable"&lt;/STRONG&gt;&lt;/FONT&gt; (screenshot attached). I am not able to understand why? I've checked and my env active gate is up and running.&lt;/P&gt;&lt;P&gt;Also how does the flow work? Dynatrace AWS pushes the metrics to Dynatrace or is it Dynatrace which pulls the metrics from AWS?&lt;/P&gt;&lt;P&gt;Any help on this is really appreciated.&lt;/P&gt;&lt;P&gt;Best Regards,&lt;BR /&gt;Shashank&lt;/P&gt;</description>
      <pubDate>Sun, 01 Oct 2023 22:16:01 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Cloud-platforms/Dynatrace-set-up-on-AWS/m-p/224306#M1349</guid>
      <dc:creator>agrawal_shashan</dc:creator>
      <dc:date>2023-10-01T22:16:01Z</dc:date>
    </item>
    <item>
      <title>Re: Dynatrace set up on AWS</title>
      <link>https://community.dynatrace.com/t5/Cloud-platforms/Dynatrace-set-up-on-AWS/m-p/224326#M1351</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/22988"&gt;@agrawal_shashan&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Is it possible that the ActiveGate you're set up is not correctly linked to your tenant, as in, there is no communication to it somehow? Does it appear if you search for it under Deployment Status -&amp;gt; ActiveGates? And does it have the AWS module enabled?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="victor_balbuena_0-1696232992917.png" style="width: 400px;"&gt;&lt;img src="https://community.dynatrace.com/t5/image/serverpage/image-id/14393i1DA936E94D1201E9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="victor_balbuena_0-1696232992917.png" alt="victor_balbuena_0-1696232992917.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;For your second question, it is the ActiveGate itself that connects to your AWS account, polls the metrics from AWS Cloudwatch and then sends them to the Dynatrace cluster - everything happens in the ActiveGate.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Oct 2023 08:39:23 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Cloud-platforms/Dynatrace-set-up-on-AWS/m-p/224326#M1351</guid>
      <dc:creator>victor_balbuena</dc:creator>
      <dc:date>2023-10-02T08:39:23Z</dc:date>
    </item>
    <item>
      <title>Re: Dynatrace set up on AWS</title>
      <link>https://community.dynatrace.com/t5/Cloud-platforms/Dynatrace-set-up-on-AWS/m-p/224342#M1352</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/3978"&gt;@victor_balbuena&lt;/a&gt;&amp;nbsp;Thanks for the response. So right now I have an EC2 instance in a AWS account (XYZ) where I have also deployed Dynatrace Active gate. This EC2 instance has connectivity open to our Dynatrace Managed Cluster.&lt;/P&gt;&lt;P&gt;And in Dynatrace UI also I am just trying to connect to this same AWS account (XYZ) for now but it gives me that error which I pasted. Just trying to understand when I click on connect, what happens? Does Dynatrace managed cluster tries to connect to AWS or is it Env Active gate on AWS tries to pull the metrics from the same account?&lt;/P&gt;&lt;P&gt;FYI.. AWS module is enabled on the Env Active gate.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Oct 2023 09:00:58 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Cloud-platforms/Dynatrace-set-up-on-AWS/m-p/224342#M1352</guid>
      <dc:creator>agrawal_shashan</dc:creator>
      <dc:date>2023-10-02T09:00:58Z</dc:date>
    </item>
    <item>
      <title>Re: Dynatrace set up on AWS</title>
      <link>https://community.dynatrace.com/t5/Cloud-platforms/Dynatrace-set-up-on-AWS/m-p/224343#M1353</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/3978"&gt;@victor_balbuena&lt;/a&gt;&amp;nbsp;I was actually connecting from wrong Dynatrace Env but I rectified it and now trying from the correct tenant/env. But now I am getting a different error which says &lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;"Invalid Credentials".&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Also below are the logs from Env Active gate -&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;2023-10-02 09:09:34 UTC INFO    [&amp;lt;XXXXXXX-XXXXXXXX-XXXXXX&amp;gt;] [&amp;lt;vtopology.provider&amp;gt;, RoleCredentialsProvider] Cannot obtain CLIENT short term credentials for arn&lt;img class="lia-deferred-image lia-image-emoji" src="https://community.dynatrace.com/html/@F9676CCDE08B8746467ACFFDC4C9827E/images/emoticons/aws.png" alt=":aws:" title=":aws:" /&gt;iam::XXXXXXXXXXXX:role/Dynatrace_ActiveGate_role ; AWSCredentialsImpl {identifier: XXXXXXXX, accessKey: null, secretKey: null, tenantUUID: XXXXXXX-XXXXXXXX-XXXXXX, iamRole: Dynatrace_ActiveGate_role, accountId: XXXXXXXXX, externalId: *****, label: Dynatrace Integration, partition: aws, detectedPartition: aws, monitorOnlyTaggedEntities: false, includeTags: [], excludeTags: [], excludedRegions: [], logConfigSQSesEnabled: false, logConfigSQSes: [], version: 2.0, legacyServices: [ebs_builtin, lambda_builtin, ELB_builtin, loadbalancer_builtin, s3_builtin, dynamodb_builtin, ec2_builtin, asg_builtin, rds_builtin], services: []} [Suppressing further identical messages for 10 minutes]
com.amazonaws.SdkClientException: Unable to execute HTTP request: Connect to sts.amazonaws.com:443 [sts.amazonaws.com/209.54.180.124] failed: connect timed out
        at com.amazonaws.http.AmazonHttpClient$RequestExecutor.handleRetryableException(AmazonHttpClient.java:1219)

2023-10-02 09:09:34 UTC WARNING [&amp;lt;XXXXXXX-XXXXXXXX-XXXXXX&amp;gt;] [&amp;lt;vtopology.provider&amp;gt;, AWSFastCheckCallable] Credentials refresh failed: {status: ERROR_BAD_CREDENTIALS, statusInfo: Service failed to assume role provided in credentials, credentials: AWSCredentialsImpl {identifier: XXXXXXXXX, accessKey: null, tenantUUID: XXXXXXX-XXXXXXXX-XXXXXX, iamRole: Dynatrace_ActiveGate_role, accountId: XXXXXXXX, externalId: *****, label: Dynatrace Integration, version: 2.0}, exception: com.amazonaws.SdkClientException: Unable to execute HTTP request: Connect to sts.amazonaws.com:443 [sts.amazonaws.com/209.54.180.124] failed: connect timed out}&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Oct 2023 09:20:16 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Cloud-platforms/Dynatrace-set-up-on-AWS/m-p/224343#M1353</guid>
      <dc:creator>agrawal_shashan</dc:creator>
      <dc:date>2023-10-02T09:20:16Z</dc:date>
    </item>
    <item>
      <title>Re: Dynatrace set up on AWS</title>
      <link>https://community.dynatrace.com/t5/Cloud-platforms/Dynatrace-set-up-on-AWS/m-p/224348#M1354</link>
      <description>&lt;P&gt;When you click on connect, it's the ActiveGate reaching out to test the connection to AWS, so it acknowledges the connection works before it's set up. Dynatrace Managed is not involved in this step. Once it is set up, the ActiveGate will try to send the data to Dynatrace Managed, but Dynatrace Managed does not reach out to any resource ever.&lt;/P&gt;&lt;P&gt;As per the issue, we are falling into AWS teritory now, so it might make more sense if some expert from AWS takes a look or you talk to Dynatrace support directly. Having said that, something you can look into is the outbound security rules of your EC2 instance (where the ActiveGate is running), to allow for requests and data to leave the ActiveGate.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Oct 2023 10:15:31 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Cloud-platforms/Dynatrace-set-up-on-AWS/m-p/224348#M1354</guid>
      <dc:creator>victor_balbuena</dc:creator>
      <dc:date>2023-10-02T10:15:31Z</dc:date>
    </item>
    <item>
      <title>Re: Dynatrace set up on AWS</title>
      <link>https://community.dynatrace.com/t5/Cloud-platforms/Dynatrace-set-up-on-AWS/m-p/224356#M1355</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/3978"&gt;@victor_balbuena&lt;/a&gt;&amp;nbsp;Your information has been immensly helpful. Thank you very much.&lt;/P&gt;&lt;P&gt;Again looking at this &lt;A href="https://www.dynatrace.com/support/help/shortlink/aws-managed-deployment#access-method" target="_self"&gt;documentation&lt;/A&gt; it says &lt;EM&gt;"Make sure that your Environment ActiveGate or Managed Cluster has a working connection to AWS. Configure your proxy for&amp;nbsp;&lt;A class="" title="Learn how to configure a proxy connection if you can't reach the internet directly." href="https://www.dynatrace.com/support/help/managed-cluster/configuration/can-i-use-a-proxy-for-internet-access" target="_blank" rel="noopener"&gt;Managed&lt;/A&gt;&amp;nbsp;or&amp;nbsp;&lt;A class="" title="Learn how to configure ActiveGate properties to set up a proxy." href="https://www.dynatrace.com/support/help/setup-and-configuration/dynatrace-activegate/configuration/set-up-proxy-authentication-for-activegate" target="_blank" rel="noopener"&gt;ActiveGate&lt;/A&gt;, or allow access to&amp;nbsp;*.amazonaws.com&amp;nbsp;in your firewall settings.&lt;/EM&gt;"&amp;nbsp;&lt;/P&gt;&lt;P&gt;And in the logs I can see its trying to make a connection to&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;sts.amazonaws.com:443&lt;/PRE&gt;&lt;P&gt;but failing. Trying to understand if it is the Active gate which tries to make this connection?&lt;/P&gt;&lt;P&gt;Best Regards,&lt;BR /&gt;Shashank&lt;/P&gt;</description>
      <pubDate>Mon, 02 Oct 2023 11:47:35 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Cloud-platforms/Dynatrace-set-up-on-AWS/m-p/224356#M1355</guid>
      <dc:creator>agrawal_shashan</dc:creator>
      <dc:date>2023-10-02T11:47:35Z</dc:date>
    </item>
    <item>
      <title>Re: Dynatrace set up on AWS</title>
      <link>https://community.dynatrace.com/t5/Cloud-platforms/Dynatrace-set-up-on-AWS/m-p/224357#M1356</link>
      <description>&lt;P&gt;Yes, it is the ActiveGate in this case&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Oct 2023 11:55:30 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Cloud-platforms/Dynatrace-set-up-on-AWS/m-p/224357#M1356</guid>
      <dc:creator>victor_balbuena</dc:creator>
      <dc:date>2023-10-02T11:55:30Z</dc:date>
    </item>
    <item>
      <title>Re: Dynatrace set up on AWS</title>
      <link>https://community.dynatrace.com/t5/Cloud-platforms/Dynatrace-set-up-on-AWS/m-p/224359#M1357</link>
      <description>&lt;P&gt;Hi Agrawal,&lt;/P&gt;&lt;P data-unlink="true"&gt;Did you change MonitoringRoleName after upload&lt;SPAN&gt;&amp;nbsp;YAML file from&amp;nbsp;github role_based_access_monitored_account_template.yml in &lt;STRONG&gt;Stack Details&lt;/STRONG&gt;?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Pawel_Zalewski_0-1696247834402.png" style="width: 400px;"&gt;&lt;img src="https://community.dynatrace.com/t5/image/serverpage/image-id/14399i3955A76CF71E0A4F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Pawel_Zalewski_0-1696247834402.png" alt="Pawel_Zalewski_0-1696247834402.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;In your screenshot I see in field "&lt;SPAN&gt;IAM role that Dynatrace should use to get monitoring data":&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Dynatrace_ActiveGate_role&lt;/P&gt;&lt;P&gt;but in default is:&lt;/P&gt;&lt;P&gt;Dynatrace_monitoring_role&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;Paweł&lt;/P&gt;</description>
      <pubDate>Mon, 02 Oct 2023 12:04:59 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Cloud-platforms/Dynatrace-set-up-on-AWS/m-p/224359#M1357</guid>
      <dc:creator>Pawel_Zalewski</dc:creator>
      <dc:date>2023-10-02T12:04:59Z</dc:date>
    </item>
  </channel>
</rss>

