AWS Config 변경 감지 알람이 없는 CloudWatch

AWS Config 변경을 CloudWatch 알람으로 모니터링하세요.

설명

AWS Config의 기록 중지나 전송 설정 변경은 리소스 상태를 추적하는 데 영향을 줍니다. CloudTrail 이벤트를 CloudWatch 로그 메트릭 필터와 알람에 연결해 이런 변경을 확인하세요.

잠재적 영향

알림이 없으면 설정 변경으로 인한 기록 공백을 늦게 발견할 수 있습니다.

해결 방법

구성 레코더와 전송 채널의 변경 이벤트를 수집하세요. 필터가 발행하는 지표의 이름과 네임스페이스에 알람을 연결하고 담당자가 받을 알림 작업을 설정하세요.

예시

예시는 알람의 지표 연결을 비교합니다. CloudTrail의 로그 전달, 로그 그룹, 알림 수신 대상은 별도로 구성해야 합니다.

변경 전

hcl
resource "aws_cloudwatch_log_metric_filter" "example" {
  name           = "CIS-AWSConfigChanges"
  pattern        = "{ ($.eventSource = \"config.amazonaws.com\") && (($.eventName=StopConfigurationRecorder)||($.eventName=DeleteDeliveryChannel)||($.eventName=PutDeliveryChannel)||($.eventName=PutConfigurationRecorder)) }"
  log_group_name = aws_cloudwatch_log_group.CIS_CloudWatch_LogsGroup.name

  metric_transformation {
    name      = "CIS-AWSConfigChanges"
    namespace = "CIS_Metric_Alarm_Namespace"
    value     = "1"
  }
}

resource "aws_cloudwatch_metric_alarm" "example" {
  alarm_name          = "CIS-3.9-AWSConfigChanges"
  comparison_operator = "GreaterThanOrEqualToThreshold"
  evaluation_periods  = "1"
  metric_name         = "XXXX NOT YOUR FILTER XXXX"
  namespace           = "CIS_Metric_Alarm_Namespace"
  period              = "300"
  statistic           = "Sum"
  threshold           = "1"
}

변경 후

hcl
resource "aws_cloudwatch_log_metric_filter" "example" {
  name           = "CIS-AWSConfigChanges"
  pattern        = "{ ($.eventSource = \"config.amazonaws.com\") && (($.eventName=StopConfigurationRecorder)||($.eventName=DeleteDeliveryChannel)||($.eventName=PutDeliveryChannel)||($.eventName=PutConfigurationRecorder)) }"
  log_group_name = aws_cloudwatch_log_group.CIS_CloudWatch_LogsGroup.name

  metric_transformation {
    name      = "CIS-AWSConfigChanges"
    namespace = "CIS_Metric_Alarm_Namespace"
    value     = "1"
  }
}

resource "aws_cloudwatch_metric_alarm" "example" {
  alarm_name          = "CIS-3.9-AWSConfigChanges"
  comparison_operator = "GreaterThanOrEqualToThreshold"
  evaluation_periods  = "1"
  metric_name         = aws_cloudwatch_log_metric_filter.example.id
  namespace           = "CIS_Metric_Alarm_Namespace"
  period              = "300"
  statistic           = "Sum"
  threshold           = "1"
}

참조