Troubleshooting
This section provides troubleshooting instructions for deploying and using the solution.
If these instructions don’t address your issue, Contact AWS Support provides instructions for opening an AWS Support case for this solution.
Problem: Failed job
If a job fails for any of the assessments, the web UI will display an error message, and the Job History page will show the status of the job as FAILED.
Resolution
If you wish to determine the failure’s root cause, you can use X-Ray traces to identify the resource that returned the error code. For example, if a Lambda function has failed to retrieve the list of delegated admin accounts, the X-Ray trace will direct you to the Lambda function and respective CloudWatch logs. Then you can examine the logs to determine the root cause. In addition, X-Ray service maps identify services where errors are occurring, connections with high latency, or traces for requests that were unsuccessful. These maps can be helpful, for example, when investigating APIs and their downstream services.
For example, if your job failed due to the following error:
"Error": "Lambda.TooManyRequestsException" "Cause": "Rate Exceeded
this indicates that you need to check the Lambda function concurrent executions quota
Problem: Failed Resource-Based Policies scan
This assessment type initiates an asynchronous Step Functions state machine execution to scan the resources in the spoke and member accounts.
Resolution
If the state machine execution fails, you can view the specific X-Ray trace for the failed state machine execution. You can either click on the state machine FailJob state to view the details in the Input and Output tab (see Figure 2) or use the X-Ray details to help you identify the specific resource in the state machine where the failure occurred (see Figure 3).
To view the error details, click on the resource and select the Exceptions tab. This can help you identify the Lambda function name where the failure occurred and will display the same error from the state machine output. Note that the same exception will be logged in the CloudWatch logs.
Problem: Access denied
You may receive an AccessDenied error for a specific account in Failed Tasks During Scan.
Resolution
Deploy the Spoke stack in the account to allow the scan to complete.
Problem: Undefined error
The Web UI loads, but starting scans or viewing findings causes an undefined error.
Resolution
The Web UI may be blocked from calling the API Gateway by AWS WAF. Check if your current IP address is within the range of valid IP addresses that you defined for the AWS WAF. Then open the AWS WAF console to investigate what reason your requests are blocked.
Problem: Access denied after redeploying Hub Stack
If you delete and redeploy the Hub Stack while leaving Spoke Stacks and Org Management Stack in place, you will receive Access Denied errors. The trust policy in the spoke role and org management role references the Hub Stack. During deletion of the Hub Stack, IAM will break those references and redeploying the Hub Stack does not restore them.
Resolution
Delete and redeploy the Spoke Stacks and the Org Management Stack after redeploying the Hub Stack.