For the complete documentation index, see llms.txt. This page is also available as Markdown.

AWS CloudWatch Integration Guide

Send metric alarms through an SNS webhook.

Configure AWS CloudWatch alarms to send webhook notifications to Harness AI SRE using Amazon SNS with HTTPS subscription.

Before you begin

  • Harness webhook endpoint: Create an AWS CloudWatch webhook in Harness AI SRE using the AWS CloudWatch webhook template.

  • AWS permissions: Access to create SNS topics, CloudWatch alarms, and manage subscriptions.

  • Webhook URL: Copy the webhook URL from your Harness webhook configuration.

  • CloudWatch alarms documentation: Go to CloudWatch Alarms to understand alarm configuration.

  • SNS HTTPS subscriptions: Go to SNS HTTPS Subscriptions for subscription setup details.


Architecture overview

CloudWatch alarms to SNS topic to HTTPS subscription to Harness webhook.

CloudWatch does not send webhooks directly. Use Amazon SNS as an intermediary:

  1. CloudWatch alarm state changes

  2. Alarm publishes to SNS topic

  3. SNS sends HTTPS POST to Harness webhook

  4. Harness processes the alert


Create SNS topic

Open the SNS topic creation page:

  1. Open AWS Console and go to Simple Notification Service (SNS)

  2. Click Topics, then click Create topic

Configure topic

  • Type: Standard

  • Name: harness-ai-sre-alerts

  • Display name: Harness AI SRE Alerts

  • Encryption: (Optional) Enable encryption at rest

  • Access policy: Default (allow publishers)

FIFO topics are not recommended for CloudWatch alarms as they require message group IDs.

Use Standard topic instead.

Save topic

Click Create topic and note the Topic ARN.


Create HTTPS subscription

Add subscription to topic

Start a new subscription from the topic details:

  1. In the SNS topic details, click Create subscription

Configure subscription

  • Protocol: HTTPS

  • Endpoint: Your Harness webhook URL

  • Enable raw message delivery: Uncheck (keep message wrapper)

  • Redrive policy: (Optional) Configure DLQ for failed deliveries

  • Protocol: HTTPS

  • Endpoint: Your Harness webhook URL

  • Subscription filter policy: JSON filter to process only specific alarms

This filters to only production alarms in ALARM state.

Confirm subscription

Complete the subscription confirmation handshake:

  1. Click Create subscription

  2. SNS sends a confirmation request to your Harness webhook

  3. Harness must respond with subscription confirmation

Note: Configure your Harness webhook to automatically confirm SNS subscriptions by responding to SubscribeURL in the payload.


Create CloudWatch alarm

Open the alarm creation page:

  1. Open AWS Console and go to CloudWatch

  2. Click Alarms, then click Create alarm

Select metric

  1. Click Select metric

  2. Select EC2, then select Per-Instance Metrics

  3. Select CPUUtilization for your instance

  4. Click Select metric

Conditions:

  • Threshold type: Static

  • Whenever CPUUtilization is...: Greater than 80

  • Datapoints to alarm: 2 out of 2

  1. Click Select metric

  2. Select RDS, then select Per-Database Metrics

  3. Select DatabaseConnections for your DB instance

  4. Click Select metric

Conditions:

  • Threshold type: Static

  • Whenever DatabaseConnections is...: Greater than 100

  • Datapoints to alarm: 3 out of 5

  1. Click Select metric

  2. Select Lambda, then select Per-Function Metrics

  3. Select Errors for your function

  4. Click Select metric

Conditions:

  • Threshold type: Static

  • Whenever Errors is...: Greater than 10

  • Datapoints to alarm: 1 out of 1

Configure actions

In the Configure actions step:

  • Notification:

    • Alarm state trigger: In alarm

    • Send notification to: Select your SNS topic harness-ai-sre-alerts

  • Additional actions: (Optional) Configure Auto Scaling or EC2 actions

Set alarm details

Name and describe the alarm:

  • Alarm name: Production-EC2-HighCPU

  • Alarm description: EC2 instance CPU usage above 80%

  • Treat missing data as: Choose appropriate option (default: missing)

Create alarm

Click Create alarm.


Configure field mapping in Harness

In your Harness webhook configuration, map CloudWatch/SNS payload fields to alert properties.

CloudWatch alarm SNS payload structure

Note: The Message field contains a JSON string that must be parsed.

Basic field mapping example

CloudWatch alarm data is nested in the Message field as a JSON string. Use CEL to parse:

Advanced field mapping with CEL

Parse the nested JSON message:


Test the integration

Test with CloudWatch console

Manually set the alarm state to trigger a test notification:

  1. Go to CloudWatch, then select Alarms

  2. Select your alarm

  3. Click Actions, then click Set alarm state

  4. Select In alarm

  5. Click Confirm

This manually triggers the alarm to test the integration.

Test SNS subscription

Verify in Harness

Confirm the alarm arrived and parsed correctly:

  1. Navigate to Alerts in Harness AI SRE

  2. Check that the alarm appears

  3. Verify field mapping parsed the message correctly


Available CloudWatch alarm fields

Fields in the parsed Message JSON:

Field
Description
Example

AlarmName

Alarm name

Production-EC2-HighCPU

AlarmDescription

Alarm description

EC2 instance CPU usage above 80%

AWSAccountId

AWS account ID

123456789012

NewStateValue

New alarm state

ALARM, OK, INSUFFICIENT_DATA

OldStateValue

Previous alarm state

OK, ALARM

NewStateReason

State change reason

Threshold Crossed: ...

StateChangeTime

When state changed

2025-07-01T10:10:00.000Z

Region

AWS region

US East (N. Virginia)

AlarmArn

Alarm ARN

arn:aws:cloudwatch:...

Trigger.MetricName

Metric name

CPUUtilization

Trigger.Namespace

Metric namespace

AWS/EC2

Trigger.Statistic

Statistic type

AVERAGE, SUM, MAXIMUM

Trigger.Dimensions

Metric dimensions

[{name: "InstanceId", value: "i-..."}]

Trigger.Period

Evaluation period (seconds)

300

Trigger.EvaluationPeriods

Number of periods

2

Trigger.Threshold

Alarm threshold

80.0

Trigger.ComparisonOperator

Comparison operator

GreaterThanThreshold


Advanced configuration

Filter by namespace

Only process specific AWS service alarms:

Route by region

Tag and route by AWS region:

Extract EC2 instance details

For EC2 alarms, extract instance ID:

Create composite alert messages

Combine multiple alarm details:


Troubleshooting

SNS subscription is not confirming for the Harness AI SRE webhook

Check the Harness webhook logs for SubscribeURL in the payload, configure Harness to automatically confirm subscriptions, or manually confirm the subscription in the AWS Console under SNS Subscriptions.

CloudWatch SNS Message field is not parsing in Harness AI SRE

Check the raw webhook payload in the Harness logs, verify the Message is a JSON string parsed with webhook.Message.parseJson(), and handle parsing errors before accessing nested fields.

CloudWatch alarms are not triggering the SNS webhook

Edit the alarm in CloudWatch, add a notification action with your SNS topic ARN, and ensure the alarm state matches the trigger (In alarm, OK, or Insufficient data).

SNS message signature verification is failing

SNS signs all messages with certificates. Verify the signature using the AWS SDK or the certificate URL, or accept messages without verification within a VPC or private network.


Example: complete integration

AWS SNS topic

This example uses the following SNS topic and subscription:

  • Name: harness-ai-sre-alerts

  • Type: Standard

  • Subscription:

    • Protocol: HTTPS

    • Endpoint: https://app.harness.io/gateway/ai-sre/api/webhooks/wh_abc123

    • Status: Confirmed

CloudWatch alarm

This example uses the following alarm configuration:

  • Name: Production-RDS-HighConnections

  • Metric: DatabaseConnections in the AWS/RDS namespace

  • Condition: Greater than 100 for 3 out of 5 datapoints

  • Actions: Notify harness-ai-sre-alerts when in ALARM state

Harness webhook field mapping example


Next steps


AWS official documentation

Last updated

Was this helpful?