CloudWatch alarm missing for console sign-in failures

Configure notifications for AWS console sign-in failures.

Description

Console sign-in failures can result from typing mistakes or attempts to compromise an account. Monitor failed sign-ins and investigate repeated or suspicious attempts.

Potential impact

Without notifications, repeated sign-in failures may be discovered late, delaying investigation.

Remediation

Create a log metric filter that matches both ConsoleLogin and Failed authentication. Connect an alarm to the filter’s metric, and choose a threshold and notification recipients appropriate for your environment.

Examples

The examples connect the metric to an alarm that changes state after at least one failure in five minutes. Configure CloudTrail log delivery and notification recipients separately.

Before

hcl
resource "aws_cloudwatch_log_metric_filter" "example" {
  name           = "CIS-ConsoleAuthenticationFailure"
  pattern        = "{ ($.eventName = ConsoleLogin) && ($.errorMessage = \"Failed authentication\") }"
  log_group_name = aws_cloudwatch_log_group.CIS_CloudWatch_LogsGroup.name

  metric_transformation {
    name      = "CIS-ConsoleAuthenticationFailure"
    namespace = "CIS_Metric_Alarm_Namespace"
    value     = "1"
  }
}

resource "aws_cloudwatch_metric_alarm" "example" {
  alarm_name          = "CIS-3.6-ConsoleAuthenticationFailure"
  comparison_operator = "GreaterThanOrEqualToThreshold"
  evaluation_periods  = "1"
  metric_name         = "XXX NOT YOUR FILTER"
  namespace           = "CIS_Metric_Alarm_Namespace"
  period              = "300"
  statistic           = "Sum"
  threshold           = "1"
}

After

hcl
resource "aws_cloudwatch_log_metric_filter" "example" {
  name           = "CIS-ConsoleAuthenticationFailure"
  pattern        = "{ (($.eventName = ConsoleLogin) && ($.errorMessage = \"Failed authentication\")) }"
  log_group_name = aws_cloudwatch_log_group.CIS_CloudWatch_LogsGroup.name

  metric_transformation {
    name      = "CIS-ConsoleAuthenticationFailure"
    namespace = "CIS_Metric_Alarm_Namespace"
    value     = "1"
  }
}

resource "aws_cloudwatch_metric_alarm" "example" {
  alarm_name          = "CIS-3.6-ConsoleAuthenticationFailure"
  comparison_operator = "GreaterThanOrEqualToThreshold"
  evaluation_periods  = "1"
  metric_name         = aws_cloudwatch_log_metric_filter.example.id
  namespace           = "CIS_Metric_Alarm_Namespace"
  period              = "300"
  statistic           = "Sum"
  threshold           = "1"
}

References