关于跨区域EC2实例统计与查询的技术咨询(审计用途)
Hey there, let’s walk through each of your EC2 audit needs with practical, actionable steps:
1. Count Terminated EC2 Instances
You have two main approaches depending on whether you need recently terminated instances (still retained by AWS) or historical terminated records (for longer periods):
For recently terminated instances (AWS keeps them in API responses for ~1 hour post-termination):
Use the AWS CLI to filter and count directly:aws ec2 describe-instances \ --filters "Name=instance-state-name,Values=terminated" \ --query 'length(Reservations[].Instances[])'This returns a numerical count for your default region. To check all regions, wrap this command in a loop over all AWS regions (similar to the third question below).
For historical terminated instances (beyond the 1-hour window):
Use AWS CloudTrail to trackTerminateInstancesevents. Query these events with the CLI:aws cloudtrail lookup-events \ --lookup-attributes AttributeKey=EventName,AttributeValue=TerminateInstances \ --start-time [YYYY-MM-DDTHH:MM:SSZ] \ --query 'length(Events[])'Replace the start-time with your desired date range. For cross-region visibility, ensure you have a multi-region CloudTrail trail enabled.
2. Count EC2 Instances Launched in the Past N Months (All Regions, All States)
Since the EC2 API only shows current or recently terminated instances, you’ll need to use AWS CloudTrail to track RunInstances events (this event triggers every time an instance is launched). Here’s how to do it:
Cross-region count with AWS CLI:
First, fetch all AWS regions, then loop through each to count launch events in your target timeframe:# Replace 3 with your desired number of months (1-6) MONTHS_BACK=3 START_TIME=$(date -d "-$MONTHS_BACK months" +%Y-%m-%dT%H:%M:%SZ) TOTAL=0 for region in $(aws ec2 describe-regions --query 'Regions[].RegionName' --output text); do COUNT=$(aws cloudtrail lookup-events \ --region $region \ --lookup-attributes AttributeKey=EventName,AttributeValue=RunInstances \ --start-time $START_TIME \ --query 'length(Events[])' \ --output text) TOTAL=$((TOTAL + COUNT)) echo "Region $region: $COUNT launches" done echo "Total launches across all regions in past $MONTHS_BACK months: $TOTAL"Note: If you have an organization-level CloudTrail trail, you can query the central trail instead of looping through regions for faster results.
Alternative: CloudWatch Insights:
For larger datasets, use CloudWatch Insights to analyze your CloudTrail logs. A sample query to count launches in the past 3 months:fields @timestamp, eventName, awsRegion | filter eventName = "RunInstances" | filter @timestamp > ago(3mon) | stats count() by awsRegionThis gives you a region-by-region breakdown and total count.
3. View All Running EC2 Instances Across All Regions
To get a full list of running instances in every region, use this AWS CLI script—it loops through all regions and outputs key audit details:
for region in $(aws ec2 describe-regions --query 'Regions[].RegionName' --output text); do echo -e "\n=== Running Instances in $region ===" aws ec2 describe-instances \ --region $region \ --filters "Name=instance-state-name,Values=running" \ --query 'Reservations[].Instances[].[InstanceId, InstanceType, LaunchTime, PrivateIpAddress]' \ --output table done
If you prefer the AWS Console:
- Navigate to the EC2 Dashboard
- In the top-right corner, click the region selector and choose All Regions
- Add the "Region" column to the instance table for clear visibility across regions
内容的提问来源于stack exchange,提问作者helloworld9

