1 Answer
- Newest
- Most votes
- Most comments
1
You can do this via a CloudTrail trail - AWS Organizations will log all API calls here such as inviting an account.
If your trail is sent to CloudWatch Logs you can create a Metric Filter with a filter pattern matching the events you want, and you can create an alarm on the filter.
Or you can use the CloudTrail event stream into EventBridge, which is more real-time.
See https://docs.aws.amazon.com/organizations/latest/userguide/orgs_security_incident-response.html for more info.
Relevant content
- asked 2 years ago
- asked a year ago
- AWS OFFICIALUpdated 2 years ago