Missing alarm for route table changes

Without a CloudWatch filter and alarm for AWS route table changes, changes to traffic paths can be discovered late.

Description

Without a log filter and alarm for route table events such as CreateRoute, ReplaceRoute and DeleteRoute, changes to traffic paths can be discovered late. Routing changes can affect service connectivity and security paths.

Incorrect routes can create bypass paths or communication failures. Actual reachability also depends on gateways, security groups and other settings; review these alongside the change events.

Potential impact

  • Changes to traffic paths can be discovered late.
  • Identifying outages caused by incorrect routes can take longer.
  • Responses to changes in network security paths can be delayed.

Remediation

  • Deliver important CloudTrail route table change events to CloudWatch Logs and configure a log metric filter.
  • Connect the emitted metric name and namespace to an alarm, and configure evaluation conditions and the SNS delivery path.
  • Verify coverage of the creation, replacement, deletion and association changes required for operations. Test notifications with events that satisfy the alarm conditions.

Examples

These excerpts show the filter and metric connection. Complete the comparison operator, evaluation periods, statistic and period, notification actions, CloudTrail delivery and SNS subscriptions separately. The filter name equals the metric name here, so the filter's id is referenced.

Before

hcl
resource "aws_cloudwatch_metric_alarm" "example" {
  alarm_name  = "CIS-3.13-RouteTableChanges"
  metric_name = "XXXX NOT YOUR FILTER XXXX"
  namespace   = "CIS_Metric_Alarm_Namespace"
  threshold   = "1"
}

After

hcl
resource "aws_cloudwatch_log_metric_filter" "example" {
  name           = "CIS-RouteTableChanges"
  pattern        = "{ ($.eventName = CreateRoute) || ($.eventName = CreateRouteTable) || ($.eventName = ReplaceRoute) || ($.eventName = ReplaceRouteTableAssociation) || ($.eventName = DeleteRouteTable) || ($.eventName = DeleteRoute) || ($.eventName = DisassociateRouteTable) }"
  log_group_name = aws_cloudwatch_log_group.CIS_CloudWatch_LogsGroup.name

  metric_transformation {
    name      = "CIS-RouteTableChanges"
    namespace = "CIS_Metric_Alarm_Namespace"
    value     = "1"
  }
}

resource "aws_cloudwatch_metric_alarm" "example" {
  alarm_name  = "CIS-3.13-RouteTableChanges"
  metric_name = aws_cloudwatch_log_metric_filter.example.id
  namespace   = "CIS_Metric_Alarm_Namespace"
  threshold   = "1"
}

Explanation:

  • Before: The alarm's metric name is not connected to a route change metric.
  • After: The listed routing events produce a metric connected to the alarm. Verify the required event coverage and complete the omitted settings; notifications do not block route changes.

References