Enabling Runtime Monitoring - Amazon GuardDuty
Services or capabilities described in AWS documentation might vary by Region. To see the differences applicable to the AWS European Sovereign Cloud Region, see the AWS European Sovereign Cloud User Guide.

Enabling Runtime Monitoring

Enabling Runtime Monitoring is a two-step process:

  1. Turn on Runtime Monitoring for your account. GuardDuty then accepts runtime events from your Amazon EC2 instances, Amazon ECS clusters, and Amazon EKS workloads.

  2. Manage the GuardDuty security agent for the resources you want to monitor. Based on the resource type, you can:

    • Use automated agent configuration – GuardDuty deploys the agent and establishes its connectivity.

    • Manage the agent manually – you create a VPC endpoint and manage the agent's installation and updates.

Managing the agent differs by resource type. For details, see:

When the GuardDuty security agent is deployed on an Amazon EC2 instance and receives runtime events from it, GuardDuty does not charge your AWS account for analyzing VPC flow logs from that instance. This avoids double usage costs.