AWS centralized view for logs and tracking

0

Hello Team.

I have implemented Control Tower, so I have management, audit, log archive and additional member accounts.

This setup has activated in every account some services suchs as: AWS Config, Cloudtrail, Cloudwatch logs, Lambda, EventBridge, SNS. S3 buckets (Log Archive). Additional I have enabled Controls (Guardrails), Security Hub, GuardDuty, Conformance Packs, VPC Flow Logs.

I noticed for some events I received sns notifications from Audit account, but I have some questions:

  1. When I need to make troubleshooting for some account or service, where I should see or search? Cloudtrail, Cloudwatch logs, Lambda, EventBridge, SNS. S3 buckets (Log Archive)?
  2. I have 02 S3 buckets created by Control Tower in Log Archive account, what is it stored in these buckets?, I was not be able to see the content.
  3. I have Cloudwatch Log in management account, where I think is stored all logs about every account. Is it correct, or what it is stored in CW logs?
  4. AWS Config is enabled in all accounts, but I have to enter in every account to see non-compliant rules, for example rules about conformance packs. Is there any option for centralized view for all accounts?.
  5. AWS Cloudtrail is enabled in all accounts, but I have to enter in every account to see events, or is there any option for centralized view for all accounts?
  6. SNS is enabled in Audit account, and also in every account. For which events, logs, non-compliant services I will receive sns notifications, and frequency?
  7. VPC Flow logs can publish to Cloudwatch logs or s3. Could I use the existing CW logs from management account, or s3 buckets from Log Archive, or I should create new ones?
  8. I there any way to centralized logs for vpc flow or any logs from any service to Log Archive account? and try to obtain a centralized view?
  9. Apart from email of Audit account, could I use another email as sns notification?

Thanks a lot.

Orlando
質問済み 7ヶ月前110ビュー
回答なし

ログインしていません。 ログイン 回答を投稿する。

優れた回答とは、質問に明確に答え、建設的なフィードバックを提供し、質問者の専門分野におけるスキルの向上を促すものです。

質問に答えるためのガイドライン

関連するコンテンツ