AWS Custom cloudwatch metrics data plane CPU utilization showing insufficient data
Symptom
-
Custom cloudwatch metrics data plane CPU utilization showing insufficient data or stopped working
-
less plugin-log pan_vm_plugin.log showed below error-
2024-06-27 18:19:07.105 +0530 An error occurred (SignatureDoesNotMatch) when calling the PutMetricData operation: Signature expired:
20240627T124907Z is now earlier than 20240627T124942Z (20240627T125442Z - 5 min.)
-
The above error mostly indicates the mismatch in the clock. Please make sure that the clock on both the Firewall and the AWS are in sync (NTP setting)
-
vm_cloudwatch_push_metrics ERROR: : AWS put_metric_data failed
-
The above error suggests an issue in the routing table assigned to the management interface in the AWS platform
Environment
-
pa-vm in AWS
Cause
-
NTP time sync issue
-
There is a problem with the route table which is assigned to management interface subnet
Resolution
-
Check NTP time and correct it accordingly
-
Check route table associated with management interface subnet and fix it