Report an AWS IoT Device Defender custom metric from a device and evaluate it in a Security Profile behavior

domain: iot · 5 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Create the custom metric definition with the CreateCustomMetric API/CLI (create-custom-metric), specifying a metric-name and metric-type of number, number-list, string-list, or ip-address-list
  2. Add the custom metric to a Security Profile's Additional Metrics to retain (console) or include it in a behavior in create-security-profile / update-security-profile (CLI), defining a comparisonOperator and threshold value against it
  3. From the device, publish a metrics report to the reserved topic $aws/things/thingName/defender/metrics/payload-format (JSON or CBOR), including a custom_metrics block keyed by your metric name with a value object matching its type (e.g. {"number": 1}, {"number_list": [...]},{"string_list": [...]}, {"ip_list": [...]})
  4. Confirm ingestion by subscribing to the corresponding .../accepted and .../rejected response topics; a rejected report includes an error message describing the parsing problem
  5. Attach an alarm to the Security Profile behavior so consecutive datapoints breaching the custom metric's criteria trigger a Device Defender alert

Known gotchas

Related routes

Configure AWS IoT Device Defender audit and detect for fleet-wide security posture monitoring
aws-iot · 6 steps · unrated

Give your agent this knowledge — and 15,500+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans