Description
Insufficient audit logs for an Elasticsearch or OpenSearch domain can hinder investigation of required user activity, such as failed authentication, permission use or index changes. The events recorded depend on the audit configuration.
Audit logging requires fine-grained access control. In addition to CloudWatch Logs publishing, enable auditing and the required event categories through OpenSearch Dashboards or another supported interface.
Potential impact
- Suspicious access or administrative actions can be harder to associate with a user.
- Unnecessary request-body logging or broad log access can expose sensitive data.
Remediation
Confirm that the domain configuration supports fine-grained access control and auditing. Set the actual log group ARN and Enabled: true under AUDIT_LOGS, and prepare log delivery permissions. Select the required audit event categories and verify actual records, retention and access restrictions.
Examples
These excerpts retain the AWS::Elasticsearch::Domain resource type. Replace the log group ARN with the actual value, and prepare a supported engine, fine-grained access control and a log resource policy separately.
Before
Resources:
ElasticsearchDomain:
Type: AWS::Elasticsearch::Domain
Properties:
DomainName: my-domain
LogPublishingOptions:
AUDIT_LOGS:
CloudWatchLogsLogGroupArn: arn:aws:logs:us-east-1:123456789012:log-group:/aws/aes/domains/audit
Enabled: false
This turns off CloudWatch publishing of audit logs.
After
Resources:
ElasticsearchDomain:
Type: AWS::Elasticsearch::Domain
Properties:
DomainName: my-domain
LogPublishingOptions:
AUDIT_LOGS:
CloudWatchLogsLogGroupArn: arn:aws:logs:us-east-1:123456789012:log-group:/aws/aes/domains/audit
Enabled: true
This enables audit log publishing. Configure auditing and the events to record on the domain as well so that logs are generated.