As part of AWS Metadata and Flow/Firewall Log Collection, Kentik needs permission to access selected endpoints on your behalf, as detailed in the following lists.
AWS Metadata Endpoints
EC2
DescribeAvailabilityZonesDescribeCustomerGatewaysDescribeFlowLogsDescribeInternetGatewaysDescribeInstancesDescribeNatGatewaysDescribeNetworkAclsDescribeNetworkInterfacesDescribeManagedPrefixListsDescribePrefixListsDescribeRouteTablesDescribeSecurityGroupsDescribeSubnetsDescribeTransitGatewaysDescribeTransitGatewayAttachmentsDescribeTransitGatewayVpcAttachmentsDescribeTransitGatewayRouteTablesDescribeTransitGatewayConnectsDescribeTransitGatewayConnectPeersDescribeVpcsDescribeVpcEndpointsDescribeVpcPeeringConnectionsDescribeVpnConnectionsDescribeVpnGatewaysDescribeManagedPrefixListsDescribeTransitGatewayRouteTablesSearchTransitGatewayRoutesGetManagedPrefixListEntries
Direct Connect
DescribeDirectConnectGatewaysDescribeVirtualInterfacesDescribeLagsDescribeConnections
ELB
DescribeLoadBalancers
IAM
ListAccountAliases
Network Manager (core network metadata)
ListCoreNetworksGetCoreNetworkGetCoreNetworkPolicyListAttachmentsGetNetworkRoutes
Network Firewall
ListFirewallsDescribeFirewallListFirewallPoliciesDescribeFirewallPolicyDescribeRuleGroup
Optional AWS Endpoints
To optionally get a list of accounts in an AWS organization, Kentik may need to access the following additional endpoints:
Organizations
ListAccounts
CloudWatch
ListMetricsGetMetricStatisticsGetMetricData
STS
AssumeRole
