Build Trusted Advisor check configurations for cost optimization, security, and performance with notification preferences.
Build Trusted Advisor check configurations for cost optimization, security, and performance with notification preferences.
Required Fields
CheckNameCategoryChecksOutput will appear here...Build a Trusted Advisor check monitoring configuration listing specific checks by their documented Check IDs (each check has a stable ID like Qch7DwouX1 for 'Low Utilization Amazon EC2 Instances'), grouped by category (cost_optimizing, security, performance), with OrganizationalUnitScope limiting which accounts in an AWS Organization the configuration applies to, and ExcludedResources carving out specific known-exception resources (like a deliberately low-utilization dev instance) from triggering findings. Most Trusted Advisor checks, including cost-optimization ones, require a Business or Enterprise Support plan to access programmatically or see full results, Basic/Developer support tiers only get a handful of core checks, so a configuration referencing the full check catalog silently returns incomplete results on a lower support tier.
The builder validates that CheckName, Category, and Checks all resolve before accepting the JSON as a plausible Trusted Advisor monitoring configuration; it can't verify the specific Check ID values are current and valid (Trusted Advisor's check catalog and IDs can change) or that your account's support plan actually grants access to the referenced checks, those are only confirmed against the live Trusted Advisor API.
Verify your account's actual AWS Support plan tier before building out a check configuration referencing the full cost-optimization/security/performance catalog, most of these checks are gated behind Business or Enterprise Support and return nothing meaningful on Basic/Developer tiers.
Review the ExcludedResources list periodically, an exclusion added for a legitimate temporary reason has no expiration and can quietly suppress a real, newly-relevant finding on that same resource ID indefinitely.
Scope OrganizationalUnitScope deliberately rather than defaulting to AllAccounts, mixing sandbox/dev accounts (where low utilization is often intentional) into a production cost-optimization review dilutes the signal with expected, non-actionable findings.
Was this tool helpful?
Disclaimer: This tool runs entirely in your browser. No data is sent to our servers. Always verify outputs before using them in production. AWS, Azure, and GCP are trademarks of their respective owners.