A company’s DevOps engineer works in a multi-account environment. The company uses AWS Transit Gateway to route all outbound traffic through a network operations account. In that network operations account, traffic from every account passes through a firewall appliance for inspection before proceeding to an internet gateway.
The firewall appliance sends logs to Amazon CloudWatch Logs, with event severities of CRITICAL, HIGH, MEDIUM, LOW, and INFO. The security team wants to receive an alert whenever any CRITICAL events occur.
What should the DevOps engineer do to satisfy these requirements?
Community Discussion
No comments yet. Be the first to start the discussion!
Community Discussion