Intermediate By Samson Tanimawo, PhD Published Sep 16, 2026 6 min read

AWS CLI Incident-Response Cheat Sheet

When the console is slow, the dashboard's lying, or the link is buried, these CLI commands answer the question faster.

Setup and identity

Confirm you're running in the right account and region before anything else. Mid-incident is a bad time to learn you're paged into staging.

EC2

Find the instance, check its status, restart it, or grab the console log.

ELB / ALB

Half the "service is down" incidents are actually one unhealthy target group.

RDS

Status, connections, recent events. RDS console is slow during incidents, CLI's faster.

CloudWatch

Metrics, logs, alarms. logs tail is criminally underused.

IAM and STS

Permission denied mid-incident is the worst kind of permission denied. Check the role, the policy, the boundary, in that order.

Health and Service quotas

Sometimes the answer is "AWS has the incident, not you." Check Health and quotas before you spend an hour on the wrong service.