Overview
Prerequisites
-
Good knowledge of AWS Service
- Kinesis Data Stream
- Kinesis Data Firehose
- S3 Bucket
- EC2 Instance
- Kinesis Agent
- Laptop/Desktop
- Internet Browser
- Internet connection
Challenge Instructions
- Region: Make sure to use us-east-1 region to create all the resources.
- You will be provided with the requirements of the challenge. If you are new to AWS Cloud, we recommend you go through our hands-on labs before taking this challenge.
- Challenge Duration: 90 minutes
How to submit the challenge
- After building the infrastructure, click on the Validation button, to validate if you have built the required infrastructure and completed the challenge successfully.
-
Validation status:
- Success - you have completed the challenge successfully.
- Failed - you have failed to complete the challenge.
- Once you have successfully validated the challenge, click on End Lab button to end the challenge.
Launching Challenge Environment
- To launch the challenge environment, click on the Start Challenge button.
- Please wait until the cloud environment is provisioned. It will take less than a minute to provision.
- Once the challenge is started, you will be provided with IAM Username, Password, Access Key, and Secret Access Key.
Lab guide
Sign in to AWS Management Console
- Click on the Open Console button, and you will get redirected to AWS console in a new browser tab.
- On the AWS sign-in page, leave the account id as default. Never edit/remove the 12-digit account id presents in the AWS console. Otherwise, you cannot proceed with the challenge.
- Now copy your Username and Password in the lab console to the IAM username and password in AWS console and click on the sign in button.
- Once signed in to the AWS management console, make the default AWS region as US East (N. Virginia) us-east-1.
Cloud Challenge Details
In this challenge lab, your AWS Kinesis skills are put to the test. You’ll deploy a sample website on an EC2 Linux instance, configure Apache web server to capture real-time logs, and stream them to AWS S3 using Kinesis Data Streams, Kinesis Agent, and Kinesis Firehose. This hands-on exercise will hone your skills in setting up efficient data pipelines for streaming, processing, and storing logs on AWS.Architecture Diagram

- Launch an EC2 Instance with name as “Demo_Instance”:
- AMI type: Amazon Linux 2023 AMI.
- Instance type: t2. micro
- Create Key Pair
- Create Security group with 2 ports like SSH, HTTP.
- Select an IAM Instance profile named as EC2_Role_<RANDOM_NUMBER>
- SSH into the EC2 instance.
- Host a sample website.
- Install the LAMP server.
- Install and start the HTTPD Server
- Download a sample website template using the following URL and save it in the HTML folder path /var/www/html.
- Verify the website is hosted successfully.
- Check the access logs of the website.
- Set permission of the httpd folder, so that the file will be in readable, writable, and executable mode by ec2-user.
- Add the httpd group to your EC2 instance.
- Add ec2-user to the httpd group.
- Log out completely and SSH again in EC2 Instance to verify that the httpd group exists with the groups.
- Change group ownership of /var/log/httpd directory and its contents to the httpd group.
- Change the directory permissions of /var/log/httpd and its subdirectories to add group write permissions and set the group ID on subdirectories created in the future
- Create Kinesis Data Stream named as “whiz-data-stream” and enable server-side encryption using AWS managed CMK.
- Create a S3 Bucket and enable default encryption.
- Create Kinesis Data Firehose with source as Amazon Kinesis Data Streams and destination as Amazon S3.
- Create a Firehose stream. To get Access Key & Secret Key, Navigate to IAM -> IAM Users -> Click on Terraform User -> Create Access Key
- Create and configure Kinesis Agent and check if the service is started properly.
- SSH into EC2 Instance
- Install latest version of Kinesis agent from URL
- Update the JSON file available at the path /etc/aws-kinesis/agent.json with the given content, replacing necessary fields with appropriate values:
- Stop and restart the kinesis agent to apply configuration
- Check if the service is started properly by going through the log.
- Test the real-time streaming of data by hosting the sample website on multiple browsers or generating click activity.
- Wait for logs to appear in the S3 bucket.
- Check the CloudWatch metrics of Kinesis Data Stream and Firehose.
End Challenge
- Sign Out of the AWS account.
- You have successfully completed the challenge.
- Click on End Challenge button from IP Lab Portal Labs console and wait till the process gets completed.
What gets checked
When you press Check my work, the platform verifies each of these:- Create an Amazon Kinesis Data stream — Check whether an Amazon Kinesis Data Stream is created with encryption as enabled or not
- Create an Amazon Kinesis Data Firehouse Delivery stream — Check whether an Amazon Kinesis Firehouse Delivery Stream is created
- Launch an EC2 Instance — Check whether an EC2 Instance is launched or not.
- Check EC2 Web Application Status — Check whether an EC2 Web Application is Deployed in the EC2 Instance or not.
- Create Private S3 bucket — Check whether a private S3 bucket is created or not
- check s3 object — Check whether an object is uploaded to the S3 bucket.