내용으로 건너뛰기

AWS Inspector V2 is not detecting nodes for CIS scans.

0

AWS inspector classic worked fine for CIS benchmarks on our EC2 nodes. Trying to move over to V2 there are issues detecting nodes. All CIS scans currently show no checked resources and 0 checks.

  1. I've ensured SSM is working and at the latest versions. Associations status shows success
  2. Created necessary VPC Endpoints for SSM, S3, and EC2.
  3. Allowed the proper S3 buckets via region through IAM
  4. The correct IAM policies are applied to the nodes( AmazonSSMManagedInstanceCore and AmazonInspector2ManagedCisPolicy)
  5. All the instances are Amazon Linux 2023
  6. I've validated the CIS configuration tags exist on the target instances.

I've checked the SSM logs and Inspector logs on the EC2 instances, AWS Inspector doesn't show any helpful errors or output making it hard to troubleshoot further. Any insight or thoughts would be appreciated.

질문됨 10달 전157회 조회
2개 답변
0

Please keep in mind that the CIS standards are intended for x86_64 operating systems.

Reference to documentation: Click here

AWS
전문가
답변함 9달 전
  • I appreciate the input, but these are x86_64 systems.

0

Check the CIS scan configuration to verify that target resource tags are correctly defined and present. Adding tags to a CIS scan configuration:

AWS
전문가
답변함 9달 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

관련 콘텐츠