Skip to main content

Cloud resource inventory collection for LogicMonitor licensing

Project description

LM Cloud Resource Inventory

A unified solution for collecting cloud resource counts across AWS, Azure, GCP, and OCI for LogicMonitor licensing purposes.

Overview

This tool collects resource inventory from cloud providers and calculates LogicMonitor license requirements by categorizing resources into:

  • IaaS - Virtual machines and compute instances
  • PaaS - Managed services, containers, serverless functions
  • Non-Compute - Storage, networking, and other infrastructure resources

Quick Start

Installation

python3 -m pip install "lm-cloud-inventory[all]"

Or install from source:

git clone https://github.com/logicmonitor/lm-cloud-resource-inventory.git
cd lm-cloud-resource-inventory
python3 -m pip install ".[all]"

On Windows, use the Python 3 launcher so installation targets the same Python family used by the CLI:

py -3 -m pip install "lm-cloud-inventory[all]"

Basic Usage

# Run inventory and calculate licenses
lmci run -p aws -o aws_summary.csv
lmci run -p azure -o azure_summary.csv
lmci run -p gcp -o gcp_summary.csv
lmci run -p oci -o oci_summary.csv

CLI Reference

Global Options

Option Description
-v, --verbose Enable verbose logging (shows debug info and full tracebacks)
--version Show version and exit
--help Show help message

run Command (Recommended)

Collect inventory and calculate licenses in one step. This is the primary command for most users.

lmci run -p <provider> [options]
Option Provider Description
-p, --provider All Cloud provider: aws, azure, gcp, oci (required)
-o, --output All Output CSV file (default: license_summary.csv)
-d, --detailed All Generate detailed CSV with per-region breakdown
--show-unmapped All List resource types not mapped to license categories
--profile AWS AWS CLI profile name
--region AWS AWS region for API calls (default: us-east-1)
--organization AWS IAM role name for cross-account access
--organization GCP GCP organization ID for org-wide inventory
-s, --subscription Azure Subscription ID (can be repeated for multiple)
--project GCP GCP project ID
--compartment OCI OCI compartment OCID

Examples:

# AWS - basic
lmci run -p aws

# AWS - with named profile
lmci run -p aws --profile production -o aws_prod.csv

# Azure - all subscriptions
lmci run -p azure

# Azure - specific subscriptions
lmci run -p azure -s "sub-id-1" -s "sub-id-2"

# GCP - auto-detect project from credentials
lmci run -p gcp

# GCP - explicit project
lmci run -p gcp --project my-project-id

# OCI - entire tenancy
lmci run -p oci

# OCI - specific compartment
lmci run -p oci --compartment ocid1.compartment.oc1..xxx

# Any provider - with detailed output
lmci run -p aws -d -o detailed_report.csv

collect Command

Collect inventory only (saves JSON for later calculation).

lmci collect -p <provider> [options]
Option Provider Description
-p, --provider All Cloud provider (required)
-o, --output All Output JSON file (default: inventory.json)
--profile AWS AWS CLI profile name
--region AWS AWS region for API calls (default: us-east-1)
--organization AWS IAM role name for cross-account access
--organization GCP GCP organization ID for org-wide inventory
-s, --subscription Azure Subscription ID (repeatable)
--project GCP GCP project ID
--compartment OCI OCI compartment OCID

calculate Command

Calculate licenses from an existing inventory JSON file.

lmci calculate -i <inventory.json> [options]
Option Description
-i, --input Input inventory JSON file (required)
-o, --output Output CSV file (default: license_summary.csv)
-d, --detailed Generate detailed CSV
--show-unmapped List unmapped resource types

check-deps Command

Verify that required SDK packages are installed and importable. The command also prints the Python interpreter and CLI path, which helps identify packages installed into a different Python environment.

# Check all providers
lmci check-deps

# Check a specific provider
lmci check-deps -p azure

permissions Command

Show required permissions for each cloud provider.

lmci permissions -p aws
lmci permissions -p azure
lmci permissions -p gcp
lmci permissions -p oci

Supported Cloud Providers

Provider API Used Performance
AWS AWS Resource Explorer ~2-5 minutes
Azure Azure Resource Graph ~1-2 minutes
GCP Cloud Asset Inventory ~1-2 minutes
OCI OCI Search Service ~1 minute

For a complete list of supported resources, see LogicMonitor Cloud Services Documentation.

AWS Resource Explorer Limitations

The following AWS services are not indexed by AWS Resource Explorer and will not be collected:

Service Resource Type
CloudSearch Domain
MediaConnect Flow
MediaConvert Queue
OpsWorks Stack
Q Business Application
QuickSight Dashboard (dataset/datasource are supported)
Simple Workflow (SWF) Domain
Application Migration Service Source Server
ElasticTranscoder Pipeline

If you have significant usage of these services, contact your LogicMonitor representative for manual inventory assistance.


Requirements

  • Python 3.9+
  • Cloud provider credentials configured via one of:
    • CLI tools (aws, az, gcloud, oci) - recommended for local use
    • Environment variables
    • Service account files
  • Read-only permissions (see Permissions Documentation)

Credential Setup

Configure credentials for each cloud provider before running the inventory.

AWS Credentials

Option 1: AWS CLI (Recommended)

# Install AWS CLI and configure
aws configure

# Verify
aws sts get-caller-identity

Option 2: Environment Variables

export AWS_ACCESS_KEY_ID="your-access-key"
export AWS_SECRET_ACCESS_KEY="your-secret-key"
export AWS_DEFAULT_REGION="us-east-1"

Option 3: Named Profiles

# Use a specific profile
lmci run -p aws --profile production

Resources: AWS CLI Configuration


Azure Credentials

Option 1: Azure CLI (Recommended)

# Sign in
az login

# Verify
az account list --output table

Option 2: Service Principal

export AZURE_CLIENT_ID="appId"
export AZURE_CLIENT_SECRET="password"
export AZURE_TENANT_ID="tenant"

Resources: Azure CLI Authentication


GCP Credentials

Option 1: gcloud CLI (Recommended)

# Initialize and authenticate
gcloud init
gcloud auth application-default login

# Verify
gcloud config list

Option 2: Service Account Key

export GOOGLE_APPLICATION_CREDENTIALS="/path/to/service-account-key.json"

The tool will automatically extract the project_id from the service account JSON file.

Resources: GCP Application Default Credentials


OCI Credentials

Option 1: OCI CLI (Recommended)

# Run setup wizard
oci setup config

# Verify
oci iam region list

Configuration is stored in ~/.oci/config.

Resources: OCI CLI Quickstart


Running in Cloud Shell

Each cloud provider offers a browser-based shell with credentials pre-configured - the fastest way to run the inventory tool.

Provider Cloud Shell Notes
AWS AWS CloudShell Python pre-installed, credentials automatic
Azure Azure Cloud Shell Python pre-installed, az authenticated
GCP Google Cloud Shell Python & gcloud pre-installed
OCI OCI Cloud Shell OCI CLI pre-installed

Output Files

Summary CSV

The default output includes resource type breakdown by category:

Provider,Account,Category,ResourceType,Region,Count
aws,123456789012,IaaS,ec2:instance,us-east-1,42
aws,123456789012,IaaS,ec2:instance,us-west-2,15
aws,123456789012,PaaS,lambda:function,us-east-1,28

TOTAL,,IaaS,,,57
TOTAL,,PaaS,,,28
TOTAL,,Non-Compute,,,125

Detailed CSV (with -d flag)

Same as summary but saved to a separate _detailed.csv file.

Raw Inventory JSON

The _inventory.json file contains raw resource data for analysis:

[
  {
    "provider": "aws",
    "account_id": "123456789012",
    "region": "us-east-1",
    "resource_type": "ec2:instance",
    "count": 42,
    "timestamp": "2024-12-22T10:30:00Z"
  }
]

Troubleshooting

AWS: "Resource Explorer not enabled"

AWS Resource Explorer is required. Enable it in your account:

  1. Go to AWS Resource Explorer Console
  2. Enable Resource Explorer
  3. Create an aggregator index for cross-region queries

AWS: "Access Denied"

# Verify credentials
aws sts get-caller-identity

Check Permissions Documentation for required IAM permissions.

Azure: "AuthorizationFailed"

# Verify login
az account show

Ensure you have the Reader role on the subscription(s).

GCP: "Permission denied"

# Verify auth
gcloud auth list

Ensure you have the roles/cloudasset.viewer role.

OCI: "NotAuthorizedOrNotFound"

# Verify config
cat ~/.oci/config

Ensure the policy allows: Allow group <group> to inspect all-resources in tenancy

General: "ModuleNotFoundError"

# Diagnose which dependencies are missing
lmci check-deps

# Install dependencies for a specific provider
python3 -m pip install "lm-cloud-inventory[aws]"
python3 -m pip install "lm-cloud-inventory[azure]"
python3 -m pip install "lm-cloud-inventory[gcp]"
python3 -m pip install "lm-cloud-inventory[oci]"

# Or install all providers at once
python3 -m pip install "lm-cloud-inventory[all]"

On Windows, replace python3 -m pip with py -3 -m pip.


Security & Privacy

Security:

  • Read-only access only - no write/modify/delete operations
  • Uses provider credential chains - no credential storage
  • Only communicates with cloud provider APIs

Data Collected:

  • Resource type counts
  • Account/subscription identifiers
  • Region/location information

NOT Collected:

  • Resource names or IDs
  • Resource content or data
  • Configuration details
  • Credentials or secrets

Documentation


Support

  • Pre-sales: Contact your LogicMonitor Sales Engineer
  • Customers: Contact your Customer Success Manager

License

MIT License - See LICENSE file for details.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

lm_cloud_inventory-2.1.1.tar.gz (65.2 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

lm_cloud_inventory-2.1.1-py3-none-any.whl (39.8 kB view details)

Uploaded Python 3

File details

Details for the file lm_cloud_inventory-2.1.1.tar.gz.

File metadata

  • Download URL: lm_cloud_inventory-2.1.1.tar.gz
  • Upload date:
  • Size: 65.2 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for lm_cloud_inventory-2.1.1.tar.gz
Algorithm Hash digest
SHA256 1de5514f335812b9c5500677507521675a62b22b4ced4a6bab4cc07d89db3ed7
MD5 0ff5faac00ce803ca200d6a8fc2b9cce
BLAKE2b-256 a551e022382636111909f3628693828c64ed8ad6386e7e91dc0e933d41d72c06

See more details on using hashes here.

Provenance

The following attestation bundles were made for lm_cloud_inventory-2.1.1.tar.gz:

Publisher: publish.yml on logicmonitor/lm-cloud-resource-inventory

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file lm_cloud_inventory-2.1.1-py3-none-any.whl.

File metadata

File hashes

Hashes for lm_cloud_inventory-2.1.1-py3-none-any.whl
Algorithm Hash digest
SHA256 4d71e1b9e175d91ee491c3eb9d2cc58fd7ef6eef211c1adc6f3111a4118c91d1
MD5 dec5ba9cad4784d9c5873252046220af
BLAKE2b-256 ad7a372881c885f0b6864d7001a68c52cc177cdd068231546b19f7ce133b5170

See more details on using hashes here.

Provenance

The following attestation bundles were made for lm_cloud_inventory-2.1.1-py3-none-any.whl:

Publisher: publish.yml on logicmonitor/lm-cloud-resource-inventory

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page