CloudTrail 설정 변경 감지 알람이 없는 CloudWatch

CloudTrail 구성 변경과 로깅 중지를 모니터링하세요.

설명

트레일의 생성·수정·삭제와 로깅 시작·중지는 감사 로그 수집에 영향을 줍니다. 이런 변경에 대한 알림을 설정해 의도하지 않은 기록 중단을 확인하세요.

잠재적 영향

알림이 없으면 트레일 설정 변경이나 로깅 중지로 생긴 감사 공백을 늦게 발견할 수 있습니다.

해결 방법

CreateTrail, UpdateTrail, DeleteTrail, StartLogging, StopLogging 이벤트를 로그 메트릭 필터로 수집하세요. 필터가 발행하는 지표에 알람을 연결하고 알림 작업을 구성하세요.

예시

예시는 알람을 올바른 지표에 연결합니다. CloudTrail 로그 전달과 알림 대상은 별도로 필요합니다.

변경 전

hcl
resource "aws_cloudwatch_log_metric_filter" "example" {
  name           = "CIS-CloudTrailChanges"
  pattern        = "{ ($.eventName = CreateTrail) || ($.eventName = UpdateTrail) || ($.eventName = DeleteTrail) || ($.eventName = StartLogging) || ($.eventName = StopLogging) }"
  log_group_name = aws_cloudwatch_log_group.CIS_CloudWatch_LogsGroup.name

  metric_transformation {
    name      = "CIS-CloudTrailChanges"
    namespace = "CIS_Metric_Alarm_Namespace"
    value     = "1"
  }
}

resource "aws_cloudwatch_metric_alarm" "example" {
  alarm_name          = "CIS-3.5-CloudTrailChanges"
  comparison_operator = "GreaterThanOrEqualToThreshold"
  evaluation_periods  = "1"
  metric_name         = "XXXX NOT YOUR FILTER XXXX"
  namespace           = "CIS_Metric_Alarm_Namespace"
  period              = "300"
  statistic           = "Sum"
  threshold           = "1"
}

변경 후

hcl
resource "aws_cloudwatch_log_metric_filter" "example" {
  name           = "CIS-CloudTrailChanges"
  pattern        = "{ ($.eventName = CreateTrail) || ($.eventName = UpdateTrail) || ($.eventName = DeleteTrail) || ($.eventName = StartLogging) || ($.eventName = StopLogging) }"
  log_group_name = aws_cloudwatch_log_group.CIS_CloudWatch_LogsGroup.name

  metric_transformation {
    name      = "CIS-CloudTrailChanges"
    namespace = "CIS_Metric_Alarm_Namespace"
    value     = "1"
  }
}

resource "aws_cloudwatch_metric_alarm" "example" {
  alarm_name          = "CIS-3.5-CloudTrailChanges"
  comparison_operator = "GreaterThanOrEqualToThreshold"
  evaluation_periods  = "1"
  metric_name         = aws_cloudwatch_log_metric_filter.example.id
  namespace           = "CIS_Metric_Alarm_Namespace"
  period              = "300"
  statistic           = "Sum"
  threshold           = "1"
}

참조