A guide to setting up cloudwatch agents in AWS if you do not have internet access
The folowing endpoints must be created inside you AWS VPC
ssm.region.amazonaws.com
ssmmessages.region.amazonaws.com
ec2messages.region.amazonaws.com
logs.region.amazonaws.com