Service Name | Topology | Affinity | Affinity Additional Processing | Notes |
---|---|---|---|---|
Elastic Compute Cloud (EC2) | Supported | Supported | - | VPC Flow Logs is used to get the affinity. |
Elastic Kubernetes Service (EKS) | Supported | Not Supported | - | - |
Elastic Kubernetes Service - Namespace | Supported | Not Supported | - | - |
Elastic Kubernetes Service - Pod | Supported | Supported | KB Affinity | VPC Flow Logs is used to get the following affinity types:
|
Elastic Container Registry (ECR) | Supported | Supported | Affinity is obtained through CloudTrail management events for actions such as:
| |
Virtual Private Cloud (VPC) | Supported | Not Supported | - | VPC affinity is applicable for the resources inside the VPC. |
Elastic Load Balancing | Supported | Supported | At Discovery: Obtain IP Address using CLI - Describe Network Interface | VPC Flow Logs is used to get the affinity between ELB and target instance. |
ElastiCache | Supported | Supported | At Discovery: Obtain IP Address using Network lookup - Describe Network Interface | VPC Flow Logs is used to get the affinity. It is achieved through Private IP address. |
Relational Database Service (RDS) | Supported | Supported | At Discovery: Obtain IP Address using CLI - Describe Network Interface | VPC Flow Logs is used to get the RDS affinity. Supported engines are:
|
Dynamo DB | Supported | Supported | Affinity query on: Table name | CloudTrail is used to get the DynamoDB table level affinity. |
Simple Storage Service (S3) | Supported | Supported | - | CloudTrail is used to get the S3 bucket level affinity. |
Elastic FileSystem (EFS) | Supported | Supported | At Discovery: Obtain IP Address using CLI - Describe Mount | VPC Flow Logs is used to get the affinity. |
Key Management Service (KMS) | Supported | Supported | - | CloudTrail management events are used to get the KMS affinity. |
Simple Queue Service (SQS) | Supported | Not Supported | Provider Limitation | Only management events, like create/delete are available so no affinity is possible. |
Elastic Block Store (EBS) | Supported | Not Supported | Provider Limitation | For affinity, AWS does not log read/write operations performed on EBS volume from an EC2 instance due to security and privacy reasons. |
Elastic Container Service (ECS) | Supported | Not Supported | - | - |
ECS - Service | Supported | Not Supported | - | - |
ECS - Task | Supported | Supported | - | - |
Simple Notification Service (SNS) | Supported | Supported | - | - |
Lambda | Supported | Not Supported | Provider Limitation | - |
Reserved VMS Instances | Supported | Not Supported | - | - |
Batch Compute Environment | Supported | Not Supported | - | - |
Batch Job Queue | Supported | Not Supported | - | - |
Redshift | Supported | Not Supported | - | - |
Dax | Supported | Not Supported | - | - |
Reserved Instances DB | Supported | Not Supported | - | - |
Glacier | Supported | Not Supported | - | - |
Backup | Supported | Not Supported | - | - |
Direct Connect | Supported | Not Supported | - | - |
API Gateway | Supported | Not Supported | - | - |
Route53Resolver | Supported | Not Supported | - | - |
Route53 Hosted Zone | Supported | Not Supported | - | - |
EC2 Security Groups | Supported | Not Supported | - | - |
Elastic IP | Supported | Not Supported | - | - |
Workmail | Supported | Not Supported | - | - |
Polly | Supported | Not Supported | - | - |
Comprehend | Supported | Not Supported | - | - |
Transcribe | Supported | Not Supported | - | - |
Rekognition | Supported | Not Supported | - | - |
Lex | Supported | Not Supported | - | - |
Sagemaker | Supported | Not Supported | - | - |
Macie | Supported | Not Supported | - | - |
Stack | Supported | Not Supported | - | - |
AutoScaling | Supported | Not Supported | - | - |
Cloud Watch | Supported | Not Supported | - | - |
Cloud Trail | Supported | Not Supported | - | - |
Application Auto Scaling | Supported | Not Supported | - | - |
Auto Scaling Plans | Supported | Not Supported | - | - |
Resource Group | Supported | Not Supported | - | - |
Config | Supported | Not Supported | - | - |
ACM Private CA | Supported | Not Supported | - | - |
Cloudwatch Logs | Supported | Not Supported | - | - |
Events | Supported | Not Supported | - | - |
Performance Insights | Supported | Not Supported | - | - |
SSM | Supported | Not Supported | - | - |
Pricing | Supported | Not Supported | - | - |
Certificate Manager | Supported | Not Supported | - | - |
License Manager | Supported | Not Supported | - | - |
Cost Explorer | Supported | Not Supported | - | - |
Service Catalog | Supported | Not Supported | - | - |
Cost and Usage Report | Supported | Not Supported | - | - |
Budgets | Supported | Not Supported | - | - |
Trusted Advisor | Supported | Not Supported | - | - |
Support | Supported | Not Supported | - | - |
FMS | Supported | Not Supported | - | - |
Reservation Purchase Recommendation | Supported | Not Supported | - | - |
Rightsizing Recommendations | Supported | Not Supported | - | - |
States | Supported | Not Supported | - | - |
CloudHSM | Supported | Not Supported | - | - |
Secrets | Supported | Not Supported | - | - |
Directory Service (DS) | Supported | Not Supported | - | - |
Security Token Service (STS) | Supported | Not Supported | - | - |
WAF | Supported | Not Supported | - | - |
Inspector | Supported | Not Supported | - | - |
Shield | Supported | Not Supported | - | - |
WAF - regional | Supported | Not Supported | - | - |
SecurityHub | Supported | Not Supported | - | - |
Organizations | Supported | Not Supported | - | - |
IAM Accesskey | Supported | Not Supported | - | - |
IAM Profile | Supported | Not Supported | - | - |
IAM Groups | Supported | Not Supported | - | - |
IAM Policies | Supported | Not Supported | - | - |
IAM Roles | Supported | Not Supported | - | - |
Identity And Access Management | Supported | Not Supported | - | - |
GuardDuty | Supported | Not Supported | - | - |
Kinesis | Supported | Not Supported | - | - |
Kafka | Supported | Not Supported | - | - |
Athena | Supported | Not Supported | - | - |
Firehose | Supported | Not Supported | - | - |
ElasticMapReduce | Supported | Not Supported | - | - |
Glue | Supported | Not Supported | - | - |
Kinesis Analytics | Supported | Not Supported | - | - |
Workspaces | Supported | Not Supported | - | - |
Code Deploy | Supported | Not Supported | - | - |
Code Pipelines | Supported | Not Supported | - | - |
CodeCommit | Supported | Not Supported | - | - |
CodeBuild | Supported | Not Supported | - | - |
X-Ray | Supported | Not Supported | - | - |
CodeCommitRepository - CodeRepo | Supported | Not Supported | - | - |
Elastic Search | Supported | Not Supported | - | - |
Service Name | Topology | Affinity | Affinity Additional Processing | Notes |
---|---|---|---|---|
Virtual Server for VPC | Supported | Supported | Affinity is supported through flow logs. | |
Virtual Private Cloud (VPC) | Supported | Not Supported | VPC affinity is applicable for the resources inside the VPC. | |
Object Storage - Buckets | Supported | Supported | Affinity is supported through Cloud Activity Tracker. | |
Kubernetes Clusters (VPC) | Supported | Not Supported | - | Only resources can bee seen without affinity between pods. |
Kubernetes Namespace | Supported | Not Supported | - | Only resources can bee seen without affinity between pods. |
Kubernetes Pod | Supported | Not Supported | Only resources can bee seen without affinity between pods. | |
VirtualServer (Classic) | Supported | Not Supported | Affinity cannot be supported as no logs are available. | |
BareMetalServer (Classic) | Supported | Not Supported | Affinity cannot be supported as no logs are available. | |
BareMetalServer for VPC | No CD Support | Not Supported | Common Discovery does not support BareMetalServer for VPC. | |
Service Name | Topology | Affinity | Affinity Additional Processing | Notes |
---|---|---|---|---|
Azure Kubernetes Cluster | Supported | Not Supported | - | Only resources can be seen without affinity between pods. |
Azure Kubernetes Namespace | Supported | Not Supported | - | Only resources can be seen without affinity between pods. |
Azure Kubernetes Pod | Supported | Not Supported | Only resources can be seen without affinity between pods. |
Service Name | Topology | Affinity | Affinity Additional Processing | Notes |
---|---|---|---|---|
Virtual Machine | Supported | Not Supported | - | Only resources can bee seen without affinity between pods. |
PostgreSQL | Supported | Not Supported | - | Only resources can bee seen without affinity between pods. |
Kubernetes | Supported | Not Supported | Only resources can bee seen without affinity between pods. |