Description
Console sign-in failures can result from typing mistakes or attempts to compromise an account. Monitor failed sign-ins and investigate repeated or suspicious attempts.
Potential impact
Without notifications, repeated sign-in failures may be discovered late, delaying investigation.
Remediation
Create a log metric filter that matches both ConsoleLogin and Failed authentication. Connect an alarm to the filter’s metric, and choose a threshold and notification recipients appropriate for your environment.
Examples
The examples connect the metric to an alarm that changes state after at least one failure in five minutes. Configure CloudTrail log delivery and notification recipients separately.
Before
hcl
resource "aws_cloudwatch_log_metric_filter" "example" {
name = "CIS-ConsoleAuthenticationFailure"
pattern = "{ ($.eventName = ConsoleLogin) && ($.errorMessage = \"Failed authentication\") }"
log_group_name = aws_cloudwatch_log_group.CIS_CloudWatch_LogsGroup.name
metric_transformation {
name = "CIS-ConsoleAuthenticationFailure"
namespace = "CIS_Metric_Alarm_Namespace"
value = "1"
}
}
resource "aws_cloudwatch_metric_alarm" "example" {
alarm_name = "CIS-3.6-ConsoleAuthenticationFailure"
comparison_operator = "GreaterThanOrEqualToThreshold"
evaluation_periods = "1"
metric_name = "XXX NOT YOUR FILTER"
namespace = "CIS_Metric_Alarm_Namespace"
period = "300"
statistic = "Sum"
threshold = "1"
}
After
hcl
resource "aws_cloudwatch_log_metric_filter" "example" {
name = "CIS-ConsoleAuthenticationFailure"
pattern = "{ (($.eventName = ConsoleLogin) && ($.errorMessage = \"Failed authentication\")) }"
log_group_name = aws_cloudwatch_log_group.CIS_CloudWatch_LogsGroup.name
metric_transformation {
name = "CIS-ConsoleAuthenticationFailure"
namespace = "CIS_Metric_Alarm_Namespace"
value = "1"
}
}
resource "aws_cloudwatch_metric_alarm" "example" {
alarm_name = "CIS-3.6-ConsoleAuthenticationFailure"
comparison_operator = "GreaterThanOrEqualToThreshold"
evaluation_periods = "1"
metric_name = aws_cloudwatch_log_metric_filter.example.id
namespace = "CIS_Metric_Alarm_Namespace"
period = "300"
statistic = "Sum"
threshold = "1"
}