<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to use STS regional endpoints in Monitor Amazon Web Services with Amazon CloudWatch metrics? in Cloud platforms</title>
    <link>https://community.dynatrace.com/t5/Cloud-platforms/How-to-use-STS-regional-endpoints-in-Monitor-Amazon-Web-Services/m-p/218962#M1539</link>
    <description>&lt;P&gt;Hi, I'm looking into How to use STS regional endpoints in Monitor Amazon Web Services with Amazon CloudWatch metrics.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Reading at the documentation, it seemed like it could be done.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.dynatrace.com/support/help/shortlink/aws-monitoring-guide#monitoring-prerequisites" target="_blank" rel="noopener"&gt;https://www.dynatrace.com/support/help/shortlink/aws-monitoring-guide#monitoring-prerequisites&lt;/A&gt;&lt;/P&gt;
&lt;PRE&gt;&lt;SPAN&gt;The AWS Security Token Service is a global endpoint by default. In case of using a regional endpoint,&amp;nbsp;&lt;/SPAN&gt;sts.&amp;lt;REGION&amp;gt;.amazonaws.com&lt;SPAN&gt;&amp;nbsp;needs to be accessible.&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;Therefore, we built a Region STS Endpoint in the same Private subnet as EC2 where ActiveGate was set up. However, the connection is made to the default STS global endpoint, resulting in an error.&lt;/P&gt;
&lt;PRE&gt;2023-07-26 06:48:04 UTC INFO [&amp;lt;xxx00000&amp;gt;] [&amp;lt;vtopology.provider&amp;gt;, PartitionAutoDetection] Updating partition: aws-cn -&amp;gt; aws, for credentials: AWS-monitoring [-xxxxxxxxxxxx]&lt;BR /&gt;2023-07-26 06:48:45 UTC WARNING [&amp;lt;xxx00000&amp;gt;] [&amp;lt;vtopology.provider&amp;gt;, AWSFastCheckCallable] Credentials refresh failed: {status: ERROR_BAD_CREDENTIALS, statusInfo: Service failed to assume role provided in credentials, credentials: AWSCredentialsImpl {identifier: ***********, accessKey: null, tenantUUID: xxx00000, iamRole: Dynatrace_monitoring_role, accountId: xxxxxxxxxxx, externalId: *****, label: AWS-monitoring, version: 2.0}, exception: com.amazonaws.SdkClientException: Unable to execute HTTP request: Connect to sts.amazonaws.com:443 [sts.amazonaws.com/209.54.177.164] failed: connect timed out}&lt;/PRE&gt;
&lt;P&gt;We have confirmed that the communication between EC2 with ActiveGate and the Region STS endpoint is no problem.&lt;/P&gt;
&lt;P&gt;I think I need to add or change some settings, but if anyone knows, please let me know.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;
&lt;P&gt;Yuki Ito&lt;/P&gt;</description>
    <pubDate>Thu, 08 Aug 2024 11:13:59 GMT</pubDate>
    <dc:creator>yito</dc:creator>
    <dc:date>2024-08-08T11:13:59Z</dc:date>
    <item>
      <title>How to use STS regional endpoints in Monitor Amazon Web Services with Amazon CloudWatch metrics?</title>
      <link>https://community.dynatrace.com/t5/Cloud-platforms/How-to-use-STS-regional-endpoints-in-Monitor-Amazon-Web-Services/m-p/218962#M1539</link>
      <description>&lt;P&gt;Hi, I'm looking into How to use STS regional endpoints in Monitor Amazon Web Services with Amazon CloudWatch metrics.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Reading at the documentation, it seemed like it could be done.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.dynatrace.com/support/help/shortlink/aws-monitoring-guide#monitoring-prerequisites" target="_blank" rel="noopener"&gt;https://www.dynatrace.com/support/help/shortlink/aws-monitoring-guide#monitoring-prerequisites&lt;/A&gt;&lt;/P&gt;
&lt;PRE&gt;&lt;SPAN&gt;The AWS Security Token Service is a global endpoint by default. In case of using a regional endpoint,&amp;nbsp;&lt;/SPAN&gt;sts.&amp;lt;REGION&amp;gt;.amazonaws.com&lt;SPAN&gt;&amp;nbsp;needs to be accessible.&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;Therefore, we built a Region STS Endpoint in the same Private subnet as EC2 where ActiveGate was set up. However, the connection is made to the default STS global endpoint, resulting in an error.&lt;/P&gt;
&lt;PRE&gt;2023-07-26 06:48:04 UTC INFO [&amp;lt;xxx00000&amp;gt;] [&amp;lt;vtopology.provider&amp;gt;, PartitionAutoDetection] Updating partition: aws-cn -&amp;gt; aws, for credentials: AWS-monitoring [-xxxxxxxxxxxx]&lt;BR /&gt;2023-07-26 06:48:45 UTC WARNING [&amp;lt;xxx00000&amp;gt;] [&amp;lt;vtopology.provider&amp;gt;, AWSFastCheckCallable] Credentials refresh failed: {status: ERROR_BAD_CREDENTIALS, statusInfo: Service failed to assume role provided in credentials, credentials: AWSCredentialsImpl {identifier: ***********, accessKey: null, tenantUUID: xxx00000, iamRole: Dynatrace_monitoring_role, accountId: xxxxxxxxxxx, externalId: *****, label: AWS-monitoring, version: 2.0}, exception: com.amazonaws.SdkClientException: Unable to execute HTTP request: Connect to sts.amazonaws.com:443 [sts.amazonaws.com/209.54.177.164] failed: connect timed out}&lt;/PRE&gt;
&lt;P&gt;We have confirmed that the communication between EC2 with ActiveGate and the Region STS endpoint is no problem.&lt;/P&gt;
&lt;P&gt;I think I need to add or change some settings, but if anyone knows, please let me know.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;
&lt;P&gt;Yuki Ito&lt;/P&gt;</description>
      <pubDate>Thu, 08 Aug 2024 11:13:59 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Cloud-platforms/How-to-use-STS-regional-endpoints-in-Monitor-Amazon-Web-Services/m-p/218962#M1539</guid>
      <dc:creator>yito</dc:creator>
      <dc:date>2024-08-08T11:13:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to use STS regional endpoints in Monitor Amazon Web Services with Amazon CloudWatch metrics</title>
      <link>https://community.dynatrace.com/t5/Cloud-platforms/How-to-use-STS-regional-endpoints-in-Monitor-Amazon-Web-Services/m-p/236857#M1540</link>
      <description>&lt;P&gt;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/13041"&gt;@yito&lt;/a&gt;&amp;nbsp;were you able to get this resolved?&lt;/P&gt;</description>
      <pubDate>Mon, 12 Feb 2024 19:13:01 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Cloud-platforms/How-to-use-STS-regional-endpoints-in-Monitor-Amazon-Web-Services/m-p/236857#M1540</guid>
      <dc:creator>ChadTurner</dc:creator>
      <dc:date>2024-02-12T19:13:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to use STS regional endpoints in Monitor Amazon Web Services with Amazon CloudWatch metrics</title>
      <link>https://community.dynatrace.com/t5/Cloud-platforms/How-to-use-STS-regional-endpoints-in-Monitor-Amazon-Web-Services/m-p/240776#M1597</link>
      <description>&lt;P&gt;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/14877"&gt;@ChadTurner&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm sorry I had missed your message.&lt;/P&gt;&lt;P&gt;Actually, I haven't be able to resolved this yet. I would like to know&amp;nbsp;h&lt;SPAN&gt;ow to use STS regional endpoints in Monitor Amazon Web Services with Amazon CloudWatch metrics.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2024 08:09:17 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Cloud-platforms/How-to-use-STS-regional-endpoints-in-Monitor-Amazon-Web-Services/m-p/240776#M1597</guid>
      <dc:creator>yito</dc:creator>
      <dc:date>2024-03-22T08:09:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to use STS regional endpoints in Monitor Amazon Web Services with Amazon CloudWatch metrics</title>
      <link>https://community.dynatrace.com/t5/Cloud-platforms/How-to-use-STS-regional-endpoints-in-Monitor-Amazon-Web-Services/m-p/251624#M1704</link>
      <description>&lt;P&gt;I think I am also facing the same issue which leads in the GUI to an "IAM Role does not exist or is misconfigured" is it your use case&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/13041"&gt;@yito&lt;/a&gt;&amp;nbsp; ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From Support team we were given this error logs :&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;exception: com.amazonaws.services.securitytoken.model.RegionDisabledException: STS is not activated in this region for account:xxxxxx. Your account administrator can activate STS in this region using the IAM Console.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2024 14:03:31 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Cloud-platforms/How-to-use-STS-regional-endpoints-in-Monitor-Amazon-Web-Services/m-p/251624#M1704</guid>
      <dc:creator>NicolasTr</dc:creator>
      <dc:date>2024-07-25T14:03:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to use STS regional endpoints in Monitor Amazon Web Services with Amazon CloudWatch metrics</title>
      <link>https://community.dynatrace.com/t5/Cloud-platforms/How-to-use-STS-regional-endpoints-in-Monitor-Amazon-Web-Services/m-p/252830#M1711</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/13041"&gt;@yito&lt;/a&gt;,&lt;BR /&gt;You can set the STS endpoint type using the&amp;nbsp;config file by setting these values in the file:&lt;/P&gt;&lt;PRE&gt;&lt;SPAN&gt;[default] &lt;BR /&gt;sts_regional_endpoints = regional&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;&lt;SPAN&gt;The&amp;nbsp;&lt;/SPAN&gt;config&lt;SPAN&gt;&amp;nbsp;file is located at&amp;nbsp;&lt;/SPAN&gt;~/.aws/config&lt;SPAN&gt;&amp;nbsp;on Linux or macOS, or at&amp;nbsp;&lt;/SPAN&gt;C:\Users\USERNAME\.aws\config&lt;SPAN&gt;&amp;nbsp;on Windows.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2024 15:28:22 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Cloud-platforms/How-to-use-STS-regional-endpoints-in-Monitor-Amazon-Web-Services/m-p/252830#M1711</guid>
      <dc:creator>dawid_kaszubski</dc:creator>
      <dc:date>2024-08-07T15:28:22Z</dc:date>
    </item>
  </channel>
</rss>

