Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions skills/last9-cloudwatch/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -53,7 +53,7 @@ Discover names with `label: "__name__"`. Do not invent a `step` parameter. Disti

1. **Find names and inspect samples.** The [integration guide](https://last9.io/docs/integrations/observability/aws-cloudwatch-metrics/) documents `amazonaws_com_AWS` for its stream path. Treat it as a discovery hint: exporters can use other names. Missing one prefix does not prove missing resource metrics. Discover dimensions, then execute a bounded selector. Catalog membership proves discoverability, not delivery. `prometheus_labels` may return generic keys even with `match_query`; state that limitation and use actual returned series labels. Do not invent `service_name`, `env`, `namespace`, or AWS dimensions from another metric's catalog.
2. **Verify lineage and population.** Distinguish Metric Streams, exporters, and traces using integration information and observed series. Preserve valid mixed sources; combine only when definitions, periods, and populations justify it. Choose instance, cluster, or role scope deliberately. Removing labels after selecting overlapping copies or rollups does not remove double counting.
3. **Establish semantics.** Identify the metric, unit, statistic, period, timestamp meaning, and coverage; distinguish period summaries, gauges, and cumulative counters. Use AWS definitions and ingestion mapping for units, not magnitude or an assumed unit label. Check the current guide and observed format/additional statistics rather than imposing a historical format version. If dimensions are opaque encoded values, report the resource-selection limitation; do not invent direct keys or recreate the stream.
3. **Establish semantics.** Identify the metric, unit, statistic, period, timestamp meaning, and coverage; distinguish period summaries, gauges, and cumulative counters. Treat sample timestamps as observation timestamps. In both documented Metric Streams OpenTelemetry formats ([0.7.0](https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/CloudWatch-metric-streams-formats-opentelemetry-translation.html) and [1.0.0](https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/CloudWatch-metric-streams-formats-opentelemetry-translation-100.html)) the Summary datapoint's `time_unix_nano` is the CloudWatch period `endTime`, so a verified OpenTelemetry-format stream sample is stamped at period end. Cite that source together with the verified stream lineage when a coverage claim depends on it; for exporters or unverified lineage the mapping is unknown, so label period-boundary claims as assumptions. Use AWS definitions and ingestion mapping for units, not magnitude or an assumed unit label. Check the current guide and observed format/additional statistics rather than imposing a historical format version. If dimensions are opaque encoded values, report the resource-selection limitation; do not invent direct keys or recreate the stream.
4. **Batch independent reads and reuse evidence.** Once scopes are known, batch companion Sum/Count reads and independent discovery across requested metrics. Reuse verified names, labels, raw samples, and calculations at the same scope/time. Skip redundant catalog lookups and extra calculations: a latest-period request does not need a separate weighted window average. Execute the required expression or derive the requested result from returned raw operands, check arithmetic and units, then report as soon as the requested measurements are supported. If support is unavailable, report the gap and needed evidence instead of expanding the investigation.

`prometheus_label_values` example: substitute datasource/UTC bounds and add verified resource filters.
Expand All @@ -70,7 +70,7 @@ Discover names with `label: "__name__"`. Do not invent a `step` parameter. Disti

## Query outcomes and statistics

A successful empty expression returned no values; an explicit numeric zero is a measurement. An empty ratio does **not** prove missing raw observations. Inspect each raw operand at the same verified scope/window for absent samples, zero or invalid denominators, and vector-matching differences. Invalid queries, authentication failures, and timeouts establish neither zero nor absence. Repair invalid arguments/expressions using the actual schema and discovered names, retry the scoped read, or report the blocking error.
A successful empty expression returned no values; an explicit numeric zero is a measurement. Describe an empty result as no matching samples returned for that selector and window. Do not call it not ingested, not delivered, not reported, or a data gap: those are causes that need separate evidence such as widened history, other statistics, or datasource configuration. An empty ratio does **not** prove missing raw observations. Inspect each raw operand at the same verified scope/window for absent samples, zero or invalid denominators, and vector-matching differences. Invalid queries, authentication failures, and timeouts establish neither zero nor absence. Repair invalid arguments/expressions using the actual schema and discovered names, retry the scoped read, or report the blocking error.

[Metric Streams](https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/CloudWatch-Metric-Streams.html) carry period Sum and SampleCount plus configurable statistics. Verify the series' [summary mapping](https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/CloudWatch-metric-streams-formats-opentelemetry-translation.html) before using these recipes:

Expand All @@ -81,7 +81,7 @@ A successful empty expression returned no values; an explicit numeric zero is a
| Metric whose Sum counts events | Add disjoint period Sums; divide by elapsed seconds for average events/sec only with complete coverage. Establish event semantics from the metric definition, not its suffix. |
| Gauge: storage or utilization | Report the requested level or defined aggregate. Adding observations over time is not total storage or utilization. |
| Verified cumulative exporter counter | `rate()` / `increase()` may apply with sufficient history and reset handling. Never apply them to period summaries merely because of `_sum` / `_count` suffixes. |
| Minimum, maximum, percentile | Select the actual statistic label (`quantile` if present). Maximum period p99 is peak period p99, not whole-window p99. Do not apply `histogram_quantile()` to already-quantiled values. |
| Minimum, maximum, percentile | Select the actual statistic label (`quantile` if present). In the documented [OpenTelemetry stream translation](https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/CloudWatch-metric-streams-formats-opentelemetry-translation.html), summary `quantile` 0 carries the period Minimum and `quantile` 1 the period Maximum; confirm the ingested format before relying on that mapping, because other formats and exporters expose Min/Max differently. A period Maximum is the largest value observed in that period, not the latest reading. Maximum period p99 is peak period p99, not whole-window p99. Do not apply `histogram_quantile()` to already-quantiled values. |
| Instance, cluster, role, or other rollups | Select one non-overlapping population; never add an aggregate and its constituents. |

For verified summaries, substitute observed names, selectors, and window:
Expand Down
2 changes: 1 addition & 1 deletion skills/last9-cloudwatch/references/billing.md
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ Cost exporters can expose names such as `aws_cost_*` with amortized, unblended,

## Answer an estimated-charge request

Discover the requested cost family and scope, then retrieve the latest original observation within an appropriate bounded history. For verified stream summaries, use matching Sum/SampleCount for a period average only when that is the represented statistic; otherwise select the observed AWS statistic. Report the latest estimate with currency, month/period, and original timestamp. Do not sum repeated month-to-date readings or use `rate()` / `increase()` on a charge gauge. A difference between readings is only a change in the estimate unless adjustments and period boundaries are understood.
Discover the requested cost family and scope, then retrieve the latest original observation within an appropriate bounded history. For verified stream summaries, use matching Sum/SampleCount for a period average only when that is the represented statistic; otherwise select the observed AWS statistic. A statistic label such as `quantile` identifies a period statistic (Minimum, Maximum), never the latest reading; the latest estimate is the most recent observation of the selected statistic. Report the latest estimate with currency, month/period, and original timestamp. Do not sum repeated month-to-date readings or use `rate()` / `increase()` on a charge gauge. A difference between readings is only a change in the estimate unless adjustments and period boundaries are understood.

Billing updates are sparse. A widened historical result supports a last-known estimate, not currentness; follow the shared current probe and user freshness rules. Missing billing data can reflect configuration or scope, and does not prove zero spend or stopped delivery. Do not change billing preferences as part of this investigation.

Expand Down
2 changes: 1 addition & 1 deletion skills/last9-cloudwatch/references/dynamodb.md
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ sum(sum_over_time(<consumed-capacity-sum>{<verified-scope>}[<window>]))

Confirm full period coverage before reporting a window total. Do not divide by SampleCount, use `increase()` on period summaries, or add repeated chart rollups.

If the verified data path uses period-end timestamps for period `P`, complete disjoint observations stamped `start + P`, `start + 2P`, through `end` cover the period-aligned interval `(start, end]`. A missing observation stamped exactly at `start` does not by itself leave the first period uncovered. If timestamp-to-period mapping is unverified, state that uncertainty separately.
For verified Metric Streams lineage, AWS documents period-end stamps (see the timestamp rule in [SKILL.md](../SKILL.md)): complete disjoint observations stamped `start + P`, `start + 2P`, through `end` cover the period-aligned interval `(start, end]`; an observation stamped exactly at `start` is not needed because it belongs to the preceding period. Cite that documentation and the lineage evidence in the report. For exporters or unverified lineage, report the observed stamps and state that boundary alignment is assumed.

`SuccessfulRequestLatency` is milliseconds and operation-specific; it excludes unsuccessful requests, so it is not end-to-end latency for all attempts. Throttle events, throttled requests, conditional failures, and transaction conflicts count different things. Publication conditions vary by metric: verify the definition and data path before interpreting an empty event series as zero. Missing data alone is not proof of healthy service.

Expand Down
2 changes: 1 addition & 1 deletion skills/last9-cloudwatch/references/ec2.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ Use the shared scope, statistic, and evidence rules in [SKILL.md](../SKILL.md).

For an instance request, discover and select its actual `InstanceId` dimension. AWS also supports aggregation dimensions such as `AutoScalingGroupName`, `ImageId`, and `InstanceType` for applicable metrics; do not assume all rows are per-instance or sum aggregate rows with their instances. Metric availability depends on instance type and monitoring configuration.

Basic monitoring commonly supplies five-minute periods; detailed monitoring supplies one-minute periods for supported metrics. Some metrics retain their own cadence. Inspect actual timestamps and definitions before assuming sixty-second coverage.
Basic monitoring commonly supplies five-minute periods; detailed monitoring supplies one-minute periods for supported metrics. Some metrics retain their own cadence. Inspect actual timestamps and definitions before assuming sixty-second coverage. Observed spacing establishes reporting cadence only: five-minute spacing does not confirm basic monitoring, one-minute spacing does not confirm detailed monitoring, and neither establishes where period boundaries fall, because stream configuration and ingestion can change both.

## Levels, bytes, and credits

Expand Down
2 changes: 1 addition & 1 deletion skills/last9-cloudwatch/references/s3.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ BucketSizeBytes and NumberOfObjects are [daily storage metrics](https://docs.aws

Discover bucket/storage-type dimensions. Inspect bounded raw history spanning the cadence (for example, three days), separately from the user's requested interval. Distinguish numeric zero, last-known value with original timestamp, and no observation in the requested interval.

**Daily cadence does not make an old sample current.** Apply the shared freshness rules: current probes and widened historical reads answer different questions. Preserve the raw publication timestamp and verify any time conversion or age calculation as described in [SKILL.md](../SKILL.md).
**Daily cadence does not make an old sample current.** Apply the shared freshness rules: current probes and widened historical reads answer different questions. Preserve the raw observation timestamp, which is neither the moment AWS published the metric nor the moment Last9 ingested it, and verify any time conversion or age calculation as described in [SKILL.md](../SKILL.md).

If history is empty, verify datasource, filters, configuration, statistic, and cadence before blaming ingestion. Daily cadence is one possible explanation for a gap; sample absence does not identify its cause or establish healthy delivery. Without read-only delivery evidence, whether delivery stopped remains unconfirmed. Neither “daily” nor the previous sample establishes the next publication time **or that a newer publication has not arrived**.

Expand Down
Loading