Description
Without a log filter and alarm for the creation, attachment, detachment and deletion of internet and customer gateways, changes to the network boundary can be discovered late. These changes matter for operations and security because they can affect external communication paths.
A gateway change alone does not make a service public. Actual reachability also depends on routing, security groups and other network settings.
Potential impact
- Changes to external communication paths can be discovered late.
- Investigating outages caused by incorrect gateway attachments or detachments can take longer.
- Responses to changes in network security boundaries can be delayed.
Remediation
- Deliver the required gateway change events from CloudTrail to CloudWatch Logs and configure a log metric filter.
- Connect the emitted metric name and namespace to a CloudWatch alarm, and configure evaluation conditions and the SNS delivery path.
- Check that the required operational change events are included, then verify notifications with test events that satisfy the alarm conditions.
Examples
These excerpts show the filter and metric connection. Add the comparison operator, evaluation periods, statistic and period, and notification actions; configure CloudTrail log delivery and SNS subscriptions. The filter name equals the emitted metric name here, so the filter's id is referenced.
Before
resource "aws_cloudwatch_metric_alarm" "example" {
alarm_name = "CIS-3.12-NetworkGatewayChanges"
metric_name = "XXXX NOT YOUR FILTER XXXX"
namespace = "CIS_Metric_Alarm_Namespace"
threshold = "1"
}
After
resource "aws_cloudwatch_log_metric_filter" "example" {
name = "CIS-NetworkGatewayChanges"
pattern = "{ ($.eventName = CreateCustomerGateway) || ($.eventName = DeleteCustomerGateway) || ($.eventName = AttachInternetGateway) || ($.eventName = CreateInternetGateway) || ($.eventName = DeleteInternetGateway) || ($.eventName = DetachInternetGateway) }"
log_group_name = aws_cloudwatch_log_group.CIS_CloudWatch_LogsGroup.name
metric_transformation {
name = "CIS-NetworkGatewayChanges"
namespace = "CIS_Metric_Alarm_Namespace"
value = "1"
}
}
resource "aws_cloudwatch_metric_alarm" "example" {
alarm_name = "CIS-3.12-NetworkGatewayChanges"
metric_name = aws_cloudwatch_log_metric_filter.example.id
namespace = "CIS_Metric_Alarm_Namespace"
threshold = "1"
}
Explanation:
- Before: The alarm's metric name is not connected to a metric for gateway changes.
- After: The listed gateway events produce a metric connected to the alarm. Complete the omitted alarm settings and actual delivery path to receive notifications.