QuestionQ22

Monitoring and Logging

A company uses one AWS account to test applications on Amazon EC2 instances. AWS Config is enabled in the account, and the restricted-ssh AWS Config managed rule is active.

The company requires an automated monitoring solution that provides a customized, real-time notification whenever any security group in the account is noncompliant with the restricted-ssh rule. The customized notification must include the name and ID of the noncompliant security group.

A DevOps engineer creates an Amazon Simple Notification Service (Amazon SNS) topic in the account and subscribes the appropriate personnel to that topic.

What should the DevOps engineer do next to satisfy these requirements?

Explanation

An Amazon EventBridge rule can match AWS Config rule-compliance-change events specifically for the restricted-ssh rule with a NON_COMPLIANT result. An EventBridge input transformer can extract values from the matching event, including the affected security group’s name and ID, and format them as a custom message sent to the Amazon SNS topic. AWS Config documents EventBridge support for notifications on Config Rules Compliance Change events, and EventBridge input transformers customize event data before it is delivered to an SNS target.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!