Review Elasticsearch and OpenSearch audit logging

Configure audit log generation together with CloudWatch delivery.

Description

Insufficient audit logs for an Elasticsearch or OpenSearch domain can hinder investigation of required user activity, such as failed authentication, permission use or index changes. The events recorded depend on the audit configuration.

Audit logging requires fine-grained access control. In addition to CloudWatch Logs publishing, enable auditing and the required event categories through OpenSearch Dashboards or another supported interface.

Potential impact

  • Suspicious access or administrative actions can be harder to associate with a user.
  • Unnecessary request-body logging or broad log access can expose sensitive data.

Remediation

Confirm that the domain configuration supports fine-grained access control and auditing. Set the actual log group ARN and Enabled: true under AUDIT_LOGS, and prepare log delivery permissions. Select the required audit event categories and verify actual records, retention and access restrictions.

Examples

These excerpts retain the AWS::Elasticsearch::Domain resource type. Replace the log group ARN with the actual value, and prepare a supported engine, fine-grained access control and a log resource policy separately.

Before

yaml
Resources:
  ElasticsearchDomain:
    Type: AWS::Elasticsearch::Domain
    Properties:
      DomainName: my-domain
      LogPublishingOptions:
        AUDIT_LOGS:
          CloudWatchLogsLogGroupArn: arn:aws:logs:us-east-1:123456789012:log-group:/aws/aes/domains/audit
          Enabled: false

This turns off CloudWatch publishing of audit logs.

After

yaml
Resources:
  ElasticsearchDomain:
    Type: AWS::Elasticsearch::Domain
    Properties:
      DomainName: my-domain
      LogPublishingOptions:
        AUDIT_LOGS:
          CloudWatchLogsLogGroupArn: arn:aws:logs:us-east-1:123456789012:log-group:/aws/aes/domains/audit
          Enabled: true

This enables audit log publishing. Configure auditing and the events to record on the domain as well so that logs are generated.

References