A production account requires that every Amazon EC2 instance that has been manually logged in to be terminated within 24 hours. All applications in the production account use Auto Scaling groups with the Amazon CloudWatch Logs agent configured.
How can this process be automated?
A Create a CloudWatch Logs subscription to an AWS Step Functions application. Configure an AWS Lambda function to add a tag to the EC2 instance that produced the login event and mark the instance to be decommissioned. Create an Amazon EventBridge rule to invoke a second Lambda function once a day that will terminate all instances with this tag. B Create an Amazon CloudWatch alarm that will be invoked by the login event. Send the notification to an Amazon Simple Notification Service (Amazon SNS) topic that the operations team is subscribed to, and have them terminate the EC2 instance within 24 hours. C Create an Amazon CloudWatch alarm that will be invoked by the login event. Configure the alarm to send to an Amazon Simple Queue Service (Amazon SQS) queue. Use a group of worker instances to process messages from the queue, which then schedules an Amazon EvantBridge rule to be invoked. D Create a CloudWatch Logs subscription in an AWS Lambda function. Configure the function to add a tag to the EC2 instance that produced the login event and mark the instance to be decommissioned. Create an Amazon EventBridge rule to invoke a daily Lambda function that terminates all instances with this tag. Show Answer Answer Explanation A CloudWatch Logs subscription filter can send matching manual-login log events to a Lambda function. That function can tag the originating EC2 instance for decommissioning, and an Amazon EventBridge daily schedule can invoke another Lambda function to terminate all instances with that tag. This provides an automated cleanup process within the required time window; Auto Scaling groups can replace terminated application instances as needed.
Learn more
Community Discussion