QuestionQ41

Incident and Event Response

A company’s DevOps engineer works in a multi-account environment. The company uses AWS Transit Gateway to route all outbound traffic through a network operations account. In that network operations account, traffic from every account passes through a firewall appliance for inspection before proceeding to an internet gateway.

The firewall appliance sends logs to Amazon CloudWatch Logs, with event severities of CRITICAL, HIGH, MEDIUM, LOW, and INFO. The security team wants to receive an alert whenever any CRITICAL events occur.

What should the DevOps engineer do to satisfy these requirements?

Explanation

Amazon CloudWatch Logs metric filters can match incoming log events that contain CRITICAL and transform each match into a custom CloudWatch metric. A CloudWatch alarm on that metric can enter the ALARM state when a CRITICAL event occurs and publish a notification to an Amazon SNS topic, whose email subscription notifies the security team.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!