AWS Supported Services

This page lists the complete set of metadata labels that the AWS enrichment scraper attaches to CloudWatch metrics, for every supported AWS service. For an overview of how enrichment works and a short sample, see Enrichment Reference on the CloudWatch Metrics page.

Each table entry shows:

  • The awsNamespaces value to set in the awsNamespaces variable of your custom-values.yaml.

  • The scraper endpoint that Kloudfuse calls when enriching metadata. <region> is a placeholder for the AWS region; global services (CloudFront, Route 53) have no region segment.

  • The IAM actions required by the enrichment scraper for that namespace. Add these to your IAM policy when collecting only a subset of namespaces.

For pre-built IAM policies covering all namespaces or a core-services subset, see AWS IAM Permissions for Enrichment.

Resource Tagging

The AWS Resource Groups Tagging API is required in addition to any per-service actions listed below. Kloudfuse uses it to fetch tags across resource types.

AWS Service Enriched Metadata Fields IAM Actions Required

Resource Groups Tagging API

  • (all namespaces)

  • tagging.<region>.amazonaws.com

AWS resource tags across all supported services

  • tag:GetResources

  • tag:GetTagKeys

  • tag:GetTagValues

AI & Machine Learning

AWS Service Enriched Metadata Fields IAM Actions Required

Bedrock

  • AWS/Bedrock

  • bedrock.<region>.amazonaws.com

For Foundation Models:

  • model_name, provider_name

  • All AWS tags

  • bedrock:ListFoundationModels

  • tag:GetResources

  • tag:GetTagKeys

  • tag:GetTagValues

QBusiness

  • AWS/QBusiness

  • qbusiness.<region>.amazonaws.com

For Applications:

  • display_name

  • All AWS tags

  • qbusiness:GetApplication

  • qbusiness:ListApplications

  • qbusiness:ListTagsForResource

  • tag:GetResources

  • tag:GetTagKeys

  • tag:GetTagValues

Analytics & Data

AWS Service Enriched Metadata Fields IAM Actions Required

Athena

  • AWS/Athena

  • athena.<region>.amazonaws.com

All AWS tags on WorkGroups

  • athena:ListTagsForResource

  • athena:ListWorkGroups

  • tag:GetResources

  • tag:GetTagKeys

  • tag:GetTagValues

Glue

  • AWS/Glue

  • glue.<region>.amazonaws.com

All AWS tags on Jobs

  • glue:GetTags

  • glue:ListJobs

  • tag:GetResources

  • tag:GetTagKeys

  • tag:GetTagValues

Compute

AWS Service Enriched Metadata Fields IAM Actions Required

AutoScaling

  • AWS/AutoScaling

  • autoscaling.<region>.amazonaws.com

All AWS tags on the AutoScaling Group

  • autoscaling:DescribeAutoScalingGroups

EC2

  • AWS/EC2

  • ec2.<region>.amazonaws.com

For Instances:

  • availability_zone, image_id, instance_id, instance_type, kernel

  • iam_profile (ARN), host (instance ID), autoscaling_group, service

  • All AWS tags

For NAT Gateways:

  • natgatewayid

  • All AWS tags

  • ec2:DescribeInstances

  • ec2:DescribeNatGateways

  • ec2:DescribeVolumes

ECS

  • AWS/ECS

  • ecs.<region>.amazonaws.com

For Clusters and Services:

  • All AWS tags

  • ecs:DescribeContainerInstances

  • ecs:DescribeServices

  • ecs:ListClusters

  • ecs:ListContainerInstances

  • ecs:ListServices

  • ecs:ListTagsForResource

EKS

  • AWS/EKS

  • eks.<region>.amazonaws.com

  • arn, cluster_name, endpoint, platform_version, role_arn, status, kube_server_version

  • All AWS tags

  • eks:DescribeCluster

Lambda

  • AWS/Lambda

  • lambda.<region>.amazonaws.com

  • function_arn, functionname, memory_size, runtime

  • architecture (first in list), storage_size (EphemeralStorage Size)

  • All AWS tags

  • lambda:ListFunctions

  • lambda:ListTags

Databases

AWS Service Enriched Metadata Fields IAM Actions Required

DynamoDB

  • AWS/DynamoDB

  • dynamodb.<region>.amazonaws.com

All AWS tags on Tables

  • dynamodb:DescribeTable

  • dynamodb:ListTables

  • dynamodb:ListTagsOfResource

ElastiCache

  • AWS/ElastiCache

  • elasticache.<region>.amazonaws.com

For ElastiCache Clusters:

  • cache_node_type, name (CacheClusterId), engine, engine_version

  • preferred_availability_zone, replication_group

  • All AWS tags

For Serverless Caches:

  • name (ServerlessCacheName), engine, status, create_time

  • elasticache:DescribeCacheClusters

  • elasticache:DescribeServerlessCaches

  • elasticache:ListTagsForResource

OpenSearch

  • AWS/ES

  • es.<region>.amazonaws.com

  • elasticsearch_version (EngineVersion), name (DomainName), dedicated_master_enabled

  • instance_type, zone_awareness_enabled, ebs_enabled

  • All AWS tags

  • es:DescribeDomains

  • es:ListDomainNames

  • es:ListTags

RDS

  • AWS/RDS

  • rds.<region>.amazonaws.com

For DB Instances:

  • allocatedstoragegb, availability_zone, backupretentionperioddays

  • dbinstancearn, dbinstanceidentifier, dbinstanceclass, dbiresourceid, dbname

  • engine, engineversion, multiaz, networktype, publicly_accessible

  • secondary_availability_zone, storagetype

  • host (DbiResourceId), hostname (Endpoint Address)

  • All AWS tags

For DB Clusters:

  • allocatedstoragegb, availability_zones, backupretentionperioddays

  • dbclusterarn, dbclusterresourceid, databasename

  • engine, enginemode, engineversion, global_write_forwarding_status

  • multiaz, networktype, storagetype

  • All AWS tags

  • rds:DescribeDBClusters

  • rds:DescribeDBInstances

  • rds:ListTagsForResource

Redshift

  • AWS/Redshift

  • redshift.<region>.amazonaws.com

All AWS tags on Clusters

  • redshift:DescribeClusters

  • redshift:DescribeTags

Timestream

  • AWS/Timestream

  • ingest.timestream.<region>.amazonaws.com

For Databases:

  • database_name, arn

  • All AWS tags on the Database

For Tables:

  • table_name, database_name, arn

  • All AWS tags on the Table

  • timestream:DescribeEndpoints

  • timestream:ListDatabases

  • timestream:ListTables

  • timestream:ListTagsForResource

Media & Communication

AWS Service Enriched Metadata Fields IAM Actions Required

MediaConvert

  • AWS/MediaConvert

  • mediaconvert.<region>.amazonaws.com

For Queues:

  • name, status, type

  • All AWS tags on the Queue

  • mediaconvert:ListQueues

  • mediaconvert:ListTagsForResource

SES

  • AWS/SES

  • email.<region>.amazonaws.com

For Configuration Sets:

  • name (ConfigurationSetName)

  • tls_policy (DeliveryOptions.TlsPolicy)

  • sending_enabled (SendingOptions.SendingEnabled)

  • All AWS tags on the Configuration Set

    For SES, Kloudfuse only enriches Configuration Sets. Other SES resources are not enriched.
  • ses:GetConfigurationSet

  • ses:ListConfigurationSets

  • ses:ListTagsForResource

Messaging & Streaming

AWS Service Enriched Metadata Fields IAM Actions Required

EventBridge

  • AWS/Events

  • events.<region>.amazonaws.com

For Rules and Event Buses:

  • All AWS tags

  • events:ListEventBuses

  • events:ListRules

  • events:ListTagsForResource

Firehose

  • AWS/Firehose

  • firehose.<region>.amazonaws.com

All AWS tags on the Delivery Stream

  • firehose:DescribeDeliveryStream

  • firehose:ListDeliveryStreams

  • firehose:ListTagsForDeliveryStream

Kafka

  • AWS/Kafka

  • kafka.<region>.amazonaws.com

All AWS tags on Clusters

  • kafka:ListClustersV2

  • kafka:ListTagsForResource

Kinesis

  • AWS/Kinesis

  • kinesis.<region>.amazonaws.com

All AWS tags on Streams

  • kinesis:ListStreams

  • kinesis:ListTagsForStream

MQ

  • AWS/AmazonMQ

  • mq.<region>.amazonaws.com

  • brokerarn, brokerid, brokername, brokerstate, deploymentmode

  • enginetype, engineversion, hostinstancetype, storagetype

  • All AWS tags

  • mq:DescribeBroker

  • mq:ListBrokers

SNS

  • AWS/SNS

  • sns.<region>.amazonaws.com

All AWS tags on Topics

  • sns:ListTagsForResource

  • sns:ListTopics

SQS

  • AWS/SQS

  • sqs.<region>.amazonaws.com

All AWS tags on Queues

  • sqs:ListQueueTags

  • sqs:ListQueues

Networking & Content Delivery

AWS Service Enriched Metadata Fields IAM Actions Required

CloudFront

  • AWS/CloudFront

  • cloudfront.amazonaws.com (global)

All AWS tags on Distributions

  • cloudfront:ListDistributions

  • cloudfront:ListTagsForResource

ELB

  • AWS/ELB

  • elasticloadbalancing.<region>.amazonaws.com

  • canonicalhostedzonename, canonicalhostedzonenameid, dnsname, loadbalancername, scheme, vpcid

  • host (CanonicalHostedZoneName), hostname (CanonicalHostedZoneName), name (LoadBalancerName)

  • All AWS tags

  • elasticloadbalancing:DescribeLoadBalancers

  • elasticloadbalancing:DescribeTags

ELBv2

  • AWS/ELBV2

  • elasticloadbalancing.<region>.amazonaws.com

  • loadbalancerarn, name (LoadBalancerName), host (DNSName)

  • All AWS tags

    AWS/ELBV2 covers Application (ALB), Network (NLB), and Gateway (GWLB) load balancers. Set AWS/ELBV2 as the scraper value for all three — Kloudfuse does not accept the per-type CloudWatch namespaces (AWS/ApplicationELB, AWS/NetworkELB, AWS/GatewayELB) as enrichment scraper values.
  • elasticloadbalancing:DescribeLoadBalancers

  • elasticloadbalancing:DescribeTags

Route 53

  • AWS/Route53

  • route53.amazonaws.com (global)

All AWS tags on Health Checks

  • route53:ListHealthChecks

  • route53:ListTagsForResource

Observability

AWS Service Enriched Metadata Fields IAM Actions Required

CloudWatch Logs

  • AWS/Logs

  • logs.<region>.amazonaws.com

All AWS tags on Log Groups

  • logs:DescribeLogGroups

  • logs:ListTagsForResource

Security & Compliance

AWS Service Enriched Metadata Fields IAM Actions Required

ACM

  • AWS/CertificateManager

  • acm.<region>.amazonaws.com

All AWS tags on the Certificate

  • acm:ListCertificates

  • acm:ListTagsForCertificate

WAF

  • AWS/WAFV2

  • wafv2.<region>.amazonaws.com

For Web ACLs and Rule Groups:

  • All AWS tags

  • wafv2:ListRuleGroups

  • wafv2:ListTagsForResource

  • wafv2:ListWebACLs

Serverless & Integration

AWS Service Enriched Metadata Fields IAM Actions Required

API Gateway

  • AWS/ApiGateway

  • apigateway.<region>.amazonaws.com

  • apiid (Id)

  • All AWS tags

  • apigateway:GET

API Gateway V2

  • AWS/ApiGateway

  • apigateway.<region>.amazonaws.com

  • apiname (Name)

  • All AWS tags

  • apigateway:GET

Step Functions

  • AWS/States

  • states.<region>.amazonaws.com

For State Machines:

  • name, type

  • All AWS tags on the State Machine

For Activities:

  • name

  • All AWS tags on the Activity

  • states:ListActivities

  • states:ListStateMachines

  • states:ListTagsForResource

Storage

AWS Service Enriched Metadata Fields IAM Actions Required

EBS

  • AWS/EBS

  • ec2.<region>.amazonaws.com

  • availability_zone, multiattachenabled, outpostarn, size, snapshotid, state

  • throughput, volumeid, volume_type, volume_name

  • device (if attached)

  • All AWS tags

  • ec2:DescribeVolumes

EFS

  • AWS/EFS

  • elasticfilesystem.<region>.amazonaws.com

  • filesystemarn, name

  • aws_elasticfilesystem_default_backup (enabled/disabled)

  • All AWS tags

  • elasticfilesystem:DescribeBackupPolicy

  • elasticfilesystem:DescribeFileSystems

FSx

  • AWS/FSx

  • fsx.<region>.amazonaws.com

  • generation (1 or 2, for ONTAP only), file_system_type

  • All AWS tags

  • fsx:DescribeFileSystems

  • fsx:ListTagsForResource

S3

  • AWS/S3

  • s3.<region>.amazonaws.com

All AWS tags on the S3 Bucket

  • s3:GetBucketTagging

  • s3:ListAllMyBuckets

External References

The namespace identifiers and IAM action names on this page are sourced from the following AWS documentation: