Troubleshooting Windows EC2 instance user-data

Troubleshooting Windows EC2 instance user-data


4 min read

Often while we are troubleshooting for EC2 user data, we want to have visibility to what happens to the script at launch. Whether it failed or which line of code is not executing by the instance.

We usually have to RDP to see the log itself or use Session Manager to connect to the instance. But we often found the SSM agent is not running. It is quite frustrating and time-consuming to fix every hurdle to get to the log file.

So in this article, I'd like to share my user-data by utilizing the CloudWatch agent to push the user-data log to CloudWatch Logs.

This example will install Python and AWS CLIV2 in Windows EC2 instance.

$instanceId = (invoke-webrequest -UseBasicParsing).content
$config = '{
               "% Free Space"
               "% Committed Bytes In Use"

mkdir C:\Downloads\Amazon\AmazonCloudWatchAgent
powershell -Command "(New-Object Net.WebClient).DownloadFile('','C:\Downloads\Amazon\AmazonCloudWatchAgent\amazon-cloudwatch-agent.msi')"
   Start-Sleep 2
   $config | Set-Content 'C:\Downloads\Amazon\AmazonCloudWatchAgent\config.json'
    & "C:\Program Files\Amazon\AmazonCloudWatchAgent\amazon-cloudwatch-agent-ctl.ps1" -a fetch-config -m ec2 -s -c file:"C:\Downloads\Amazon\AmazonCloudWatchAgent\config.json"
   $agent_status = & "C:\Program Files\Amazon\AmazonCloudWatchAgent\amazon-cloudwatch-agent-ctl.ps1" -a status | ConvertFrom-Json
until($agent_status.status -eq "running")
Restart-Service AmazonSSMAgent

[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls, [Net.SecurityProtocolType]::Tls11, [Net.SecurityProtocolType]::Tls12, [Net.SecurityProtocolType]::Ssl3
[Net.ServicePointManager]::SecurityProtocol = "Tls, Tls11, Tls12, Ssl3"
iex ((new-object net.webclient).DownloadString(''))
choco install python -y
$dlurl = ""
$installerPath = Join-Path $env:TEMP (Split-Path $dlurl -Leaf)
Invoke-WebRequest $dlurl -OutFile $installerPath
Start-Process -FilePath msiexec -Args "/i $installerPath /passive" -Verb RunAs -Wait
Remove-Item $installerPath

Thanks for visiting the blog.

See you in the next post.