1. Support
  2. Integrations
  3. CloudWatch
AWS 33 nodes

CloudWatch

AWS integration · 33 node(s) including 3 trigger.

00Overview

Publish custom metrics and act on them from a flow — create or update metric and composite alarms, enable or disable their actions, and set an alarm's state to test what it triggers. Query metric statistics and math expressions, render a metric graph to a PNG image, and build or replace CloudWatch dashboards. Manage anomaly detectors, metric streams to Kinesis Data Firehose, and resource tags, all on a schedule, on approval, or in response to something happening elsewhere in your stack.

Every field below is exactly what you see in the Flomation editor. Fields marked ● live picker let you choose from a list pulled live from your account — no IDs to look up.

01Connecting CloudWatch

  1. Choose how to authenticate with the Authentication dropdown: Access Keys uses your own IAM user's keys; Assume Role (cross-account) lets Flomation assume a role in your account; Managed Role (Credential) selects a pre-configured AWS credential managed inside Flomation.
  2. For Access Keys, open the AWS console IAM → Users, create or pick a user, and attach a CloudWatch policy such as CloudWatchFullAccess (or CloudWatchReadOnlyAccess for read-only flows). On the user's Security credentials tab choose Create access key, then paste the values into AWS Access Key and AWS Secret Key — add a Session Token (optional) only when you are using temporary STS credentials.
  3. For Assume Role (cross-account), create an IAM role in your account carrying the CloudWatch permissions you need and set its trust policy to allow Flomation's AWS principal to call sts:AssumeRole. Paste the role's ARN into Role ARN to Assume, and if the trust policy requires one, fill Assume Role External ID (optional) to match.
  4. For Managed Role (Credential), simply select a pre-configured AWS Role Credential that your Flomation administrator has already set up — no keys are entered on the node.
  5. Set the Region to the AWS Region your metrics and alarms live in (e.g. eu-west-2), store your secret as a Flomation environment secret (e.g. cloudwatch_secret), and pick it in the node's AWS Secret Key field.
FieldTypeDetails
AuthenticationstringRequiredAccess Keys, Assume Role (cross-account), Managed Role (Credential)
AWS Access KeysecretRequired
AWS Secret KeysecretRequired
Session Token (optional)secret
AWS Role CredentialcredentialRequired
Good to know

Pick an Environment on your flow (Flow Settings → Environment) so the secret resolves. Secret fields never show the value — they reference ${secrets.your_secret}.

02Delete

AWS CloudWatch Delete Alarms

aws/cloudwatch/delete_alarms · Action

Delete one or more CloudWatch alarms by name.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Alarm Names (comma-separated)stringRequiredhigh-cpu,high-mem

Returns: tool_result, deleted_count

AWS CloudWatch Delete Anomaly Detector

aws/cloudwatch/delete_anomaly_detector · Action

Delete a single-metric anomaly detection model.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
NamespacestringRequiredAWS/EC2
Metric NamestringRequiredCPUUtilization
StatisticstringRequiredAverage — choices: Average, Sum, Minimum, Maximum, Sample Count
Dimensionskey_value_arrayAdd a Name and Value per dimension

Returns: tool_result

AWS CloudWatch Delete Dashboards

aws/cloudwatch/delete_dashboards · Action

Delete one or more CloudWatch dashboards by name.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Dashboard Names (comma-separated)stringRequireddash-a, dash-b

Returns: tool_result

AWS CloudWatch Delete Metric Stream

aws/cloudwatch/delete_metric_stream · Action

Delete a CloudWatch metric stream permanently.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Stream NamestringRequiredmy-metric-stream

Returns: tool_result, name

03Describe

AWS CloudWatch Describe Alarm History

aws/cloudwatch/describe_alarm_history · Action

Retrieve the state change and configuration history for alarms.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Alarm Name (optional)stringhigh-cpu
History Item Type (optional)stringchoices: Configuration Update, State Update, Action
Start Date (RFC3339, optional)string2026-07-22T00:00:00Z
End Date (RFC3339, optional)string2026-07-22T23:59:59Z

Returns: tool_result, history, count

AWS CloudWatch Describe Alarms

aws/cloudwatch/describe_alarms · Action

List metric alarms with their current state and thresholds.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Alarm Names (comma-separated, optional)stringhigh-cpu,high-mem
State (optional)stringchoices: OK, ALARM, INSUFFICIENT_DATA
Alarm Name Prefix (optional)stringprod-

Returns: tool_result, alarms, count

AWS CloudWatch Describe Alarms For Metric

aws/cloudwatch/describe_alarms_for_metric · Action

List the alarms associated with a specific metric.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
NamespacestringRequiredAWS/EC2
Metric NamestringRequiredCPUUtilization
Dimensionskey_value_arrayAdd a Name and Value per dimension
Statisticstringchoices: Average, Sum, Minimum, Maximum, Sample Count
Period (seconds)integer300

Returns: tool_result, alarms, count

AWS CloudWatch Describe Anomaly Detectors

aws/cloudwatch/describe_anomaly_detectors · Action

List anomaly detection models, filtered by namespace/metric.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Namespace (optional)stringAWS/EC2
Metric Name (optional)stringCPUUtilization

Returns: tool_result, detectors, count

04Disable

AWS CloudWatch Disable Alarm Actions

aws/cloudwatch/disable_alarm_actions · Action

Disable the configured actions for one or more alarms.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Alarm Names (comma-separated)stringRequiredhigh-cpu,high-mem

Returns: tool_result, alarm_count

05Enable

AWS CloudWatch Enable Alarm Actions

aws/cloudwatch/enable_alarm_actions · Action

Enable the configured actions for one or more alarms.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Alarm Names (comma-separated)stringRequiredhigh-cpu,high-mem

Returns: tool_result, alarm_count

06Get

AWS CloudWatch Get Dashboard

aws/cloudwatch/get_dashboard · Action

Fetch a CloudWatch dashboard's widget layout JSON and ARN by name.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Dashboard NamestringRequiredmy-dashboard

Returns: tool_result, dashboard_body, dashboard_arn

AWS CloudWatch Get Metric Data

aws/cloudwatch/get_metric_data · Action

Fetch metric data or math expression results via metric data queries.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Metric Data Queries (JSON array)stringRequired[{"Id":"m1","MetricStat":{"Metric":{"Namespace":"AWS/EC2","MetricName":"CPUUtilization"},"Period":300,"Stat":"Average"}}]
Start Time (RFC3339)stringRequired2026-07-22T00:00:00Z
End Time (RFC3339)stringRequired2026-07-22T01:00:00Z

Returns: tool_result, results, count

AWS CloudWatch Get Metric Statistics

aws/cloudwatch/get_metric_statistics · Action

Retrieve aggregated statistics for a metric over a time range.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
NamespacestringRequiredAWS/EC2
Metric NamestringRequiredCPUUtilization
Dimensionskey_value_arrayAdd a Name and Value per dimension
Start Time (RFC3339)stringRequired2026-07-22T00:00:00Z
End Time (RFC3339)stringRequired2026-07-22T01:00:00Z
Period (seconds)integerRequired300
Statistics (comma-separated)stringRequiredAverage,Maximum

Returns: tool_result, datapoints, count

AWS CloudWatch Get Metric Stream

aws/cloudwatch/get_metric_stream · Action

Retrieve the configuration and state of a CloudWatch metric stream.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Stream NamestringRequiredmy-metric-stream

Returns: tool_result, arn, state, firehose_arn, output_format

AWS CloudWatch Get Metric Widget Image

aws/cloudwatch/get_metric_widget_image · Action

Render a metric-widget definition into a PNG graph image.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Metric Widget (JSON)stringRequired{"metrics":[["AWS/EC2","CPUUtilization"]]}
Output Formatstringpng

Returns: tool_result, image_base64

07List

AWS CloudWatch List Dashboards

aws/cloudwatch/list_dashboards · Action

List CloudWatch dashboards, optionally filtered by a name prefix.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Dashboard Name Prefix (optional)stringprod-

Returns: tool_result, dashboards, count

AWS CloudWatch List Metric Streams

aws/cloudwatch/list_metric_streams · Action

List the CloudWatch metric streams in an account and Region.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy

Returns: tool_result, streams, count

AWS CloudWatch List Metrics

aws/cloudwatch/list_metrics · Action

List available CloudWatch metrics, optionally filtered.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Namespace (optional)stringAWS/EC2
Metric Name (optional)stringCPUUtilization
Dimension Filterskey_value_arrayAdd a Name and (optional) Value per filter

Returns: tool_result, metrics, count

AWS CloudWatch List Tags For Resource

aws/cloudwatch/list_tags_for_resource · Action

List the tags associated with a CloudWatch resource.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Resource ARNstringRequiredarn:aws:cloudwatch:eu-west-2:123456789012:alarm:high-cpu

Returns: tool_result, tags

08Put

AWS CloudWatch Put Anomaly Detector

aws/cloudwatch/put_anomaly_detector · Action

Create a single-metric anomaly detection model.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
NamespacestringRequiredAWS/EC2
Metric NamestringRequiredCPUUtilization
StatisticstringRequiredAverage — choices: Average, Sum, Minimum, Maximum, Sample Count
Dimensionskey_value_arrayAdd a Name and Value per dimension

Returns: tool_result

AWS CloudWatch Put Composite Alarm

aws/cloudwatch/put_composite_alarm · Action

Create or update a composite alarm from a rule over other alarms.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Alarm NamestringRequiredservice-degraded
Alarm RulestringRequiredALARM("high-cpu") OR ALARM("high-mem")
Alarm Actions (comma-separated ARNs)stringarn:aws:sns:eu-west-2:123456789012:alerts
Description (optional)string

Returns: tool_result, alarm_name

AWS CloudWatch Put Dashboard

aws/cloudwatch/put_dashboard · Action

Create or replace a CloudWatch dashboard from its widget layout JSON.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Dashboard NamestringRequiredmy-dashboard
Dashboard Body (JSON)stringRequired{"widgets":[...]}

Returns: tool_result, validation_messages

AWS CloudWatch Put Metric Alarm

aws/cloudwatch/put_metric_alarm · Action

Create or update a metric alarm on a threshold comparison.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Alarm NamestringRequiredhigh-cpu
Comparison OperatorstringRequiredchoices: Greater Than Threshold, Greater Than Or Equal To Threshold, Less Than Threshold, Less Than Or Equal To Threshold
Evaluation PeriodsintegerRequired1
Metric NamestringCPUUtilization
NamespacestringAWS/EC2
Period (seconds)integer300
Statisticstringchoices: Average, Sum, Minimum, Maximum, Sample Count
ThresholdstringRequired80
Alarm Actions (comma-separated ARNs)stringarn:aws:sns:eu-west-2:123456789012:alerts
Dimensionskey_value_arrayAdd a Name and Value per dimension
Description (optional)string
Treat Missing Data (optional)stringmissing | notBreaching | breaching | ignore

Returns: tool_result, alarm_name

AWS CloudWatch Put Metric Data

aws/cloudwatch/put_metric_data · Action

Publish one or more custom metric data points to CloudWatch.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
NamespacestringRequiredMyApp/Orders
Metric NamestringOrdersProcessed
Valuestring1
Unitstringchoices: None, Seconds, Bytes, Percent, Count, Count/Second, Milliseconds
Dimensionskey_value_arrayAdd a Name and Value per dimension
Metric Data (JSON array, overrides simple fields)string[{"MetricName":"Orders","Value":1,"Unit":"Count"}]

Returns: tool_result, datapoint_count

AWS CloudWatch Put Metric Stream

aws/cloudwatch/put_metric_stream · Action

Create or update a metric stream delivering metrics to Kinesis Data Firehose.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Stream NamestringRequiredmy-metric-stream
Firehose ARNstringRequiredarn:aws:firehose:eu-west-2:123456789012:deliverystream/my-stream
IAM Role ARNstringRequiredarn:aws:iam::123456789012:role/MetricStreamRole
Output FormatstringRequiredchoices: JSON, OpenTelemetry 0.7, OpenTelemetry 1.0
Include Filters (JSON array, optional)string[{"namespace":"AWS/EC2","metric_names":["CPUUtilization"]}]
Exclude Filters (JSON array, optional)string[{"namespace":"AWS/Logs"}]

Returns: tool_result, arn

09Set

AWS CloudWatch Set Alarm State

aws/cloudwatch/set_alarm_state · Action

Temporarily set an alarm's state to test its actions.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Alarm NamestringRequiredhigh-cpu
StatestringRequiredchoices: OK, ALARM, INSUFFICIENT_DATA
State ReasonstringRequiredManual test

Returns: tool_result, alarm_name

10Start

AWS CloudWatch Start Metric Streams

aws/cloudwatch/start_metric_streams · Action

Start streaming for one or more CloudWatch metric streams.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Stream Names (comma-separated)stringRequiredstream-a, stream-b

Returns: tool_result, count

11Stop

AWS CloudWatch Stop Metric Streams

aws/cloudwatch/stop_metric_streams · Action

Stop streaming for one or more CloudWatch metric streams.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Stream Names (comma-separated)stringRequiredstream-a, stream-b

Returns: tool_result, count

12Tag

AWS CloudWatch Tag Resource

aws/cloudwatch/tag_resource · Action

Add key-value tags to a CloudWatch resource (alarm, etc).

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Resource ARNstringRequiredarn:aws:cloudwatch:eu-west-2:123456789012:alarm:high-cpu
Tagskey_value_arrayAdd a Key and Value per tag

Returns: tool_result, resource_arn

13Untag

AWS CloudWatch Untag Resource

aws/cloudwatch/untag_resource · Action

Remove tags (by key) from a CloudWatch resource.

FieldTypeDetails
RegionstringRequiredeu-west-2
Role ARN to AssumestringRequiredarn:aws:iam::<your-account>:role/FlomationAccess
Assume Role External ID (optional)stringMust match the External ID in the role's trust policy
Resource ARNstringRequiredarn:aws:cloudwatch:eu-west-2:123456789012:alarm:high-cpu
Tag Keys (comma-separated)stringRequiredenvironment,team

Returns: tool_result, resource_arn

14Triggers

CloudWatch Alarm Trigger

trigger/cloudwatch_alarm · Trigger

Triggers a flow when a CloudWatch alarm changes state (OK, ALARM, INSUFFICIENT_DATA). Polls DescribeAlarms.

FieldTypeDetails
RegionstringRequiredeu-west-2
Alarm NamesstringComma-separated; leave blank for all alarms (optional)
Fire On StatestringAny — choices: Any state change, ALARM, OK, INSUFFICIENT_DATA
Poll Intervalstringe.g. 60s, 5m

Returns: alarm_name, state_value, previous_state, state_reason, metric_name, namespace, timestamp, triggered_at

CloudWatch Logs Trigger

trigger/cloudwatch_logs · Trigger

Triggers a flow when log events match a filter pattern in a log group. Polls FilterLogEvents.

FieldTypeDetails
RegionstringRequiredeu-west-2
Log Group NamestringRequired/aws/lambda/my-fn
Filter Patternstringe.g. ERROR (blank matches all events)
Poll Intervalstringe.g. 60s, 5m

Returns: log_group, log_stream, message, event_id, timestamp, triggered_at

CloudWatch Metric Threshold Trigger

trigger/cloudwatch_metric · Trigger

Triggers a flow when a CloudWatch metric crosses a threshold (edge-triggered). Polls GetMetricStatistics.

FieldTypeDetails
RegionstringRequiredeu-west-2
NamespacestringRequirede.g. AWS/EC2
Metric NamestringRequirede.g. CPUUtilization
DimensionsstringName=Value,Name2=Value2 (optional)
StatisticstringRequiredchoices: Average, Sum, Minimum, Maximum, Sample Count
Period (seconds)integere.g. 300
ComparisonstringRequiredchoices: Greater than, Greater than or equal, Less than, Less than or equal
ThresholdstringRequirede.g. 80
Poll Intervalstringe.g. 60s, 5m

Returns: namespace, metric_name, value, threshold, comparison, statistic, timestamp, triggered_at

15Notes & Limitations

Behaviours and constraints worth knowing before you build with these nodes.

  • CloudWatch alarms, metrics and metric streams are Region-scoped, so set Region to the Region the resources actually live in — a query against the wrong Region simply returns nothing rather than erroring.
  • The create-or-replace actions such as put_metric_alarm, put_composite_alarm and put_dashboard overwrite any existing resource of the same name in place, so reusing a name silently replaces its configuration instead of reporting a conflict.
  • Setting an alarm's state with Set Alarm State is only a temporary test override, which CloudWatch replaces automatically at the next metric evaluation.
  • Newly published custom metrics can take a few minutes to become queryable, so reading a metric immediately after publishing it may return no data points yet.
  • Get Metric Widget Image returns a rendered PNG image rather than numeric data, so wire it to a step that consumes an image (such as an email or file upload) rather than a data-processing step.