AWS centralized view for logs and tracking

0

Hello Team.

I have implemented Control Tower, so I have management, audit, log archive and additional member accounts.

This setup has activated in every account some services suchs as: AWS Config, Cloudtrail, Cloudwatch logs, Lambda, EventBridge, SNS. S3 buckets (Log Archive). Additional I have enabled Controls (Guardrails), Security Hub, GuardDuty, Conformance Packs, VPC Flow Logs.

I noticed for some events I received sns notifications from Audit account, but I have some questions:

  1. When I need to make troubleshooting for some account or service, where I should see or search? Cloudtrail, Cloudwatch logs, Lambda, EventBridge, SNS. S3 buckets (Log Archive)?
  2. I have 02 S3 buckets created by Control Tower in Log Archive account, what is it stored in these buckets?, I was not be able to see the content.
  3. I have Cloudwatch Log in management account, where I think is stored all logs about every account. Is it correct, or what it is stored in CW logs?
  4. AWS Config is enabled in all accounts, but I have to enter in every account to see non-compliant rules, for example rules about conformance packs. Is there any option for centralized view for all accounts?.
  5. AWS Cloudtrail is enabled in all accounts, but I have to enter in every account to see events, or is there any option for centralized view for all accounts?
  6. SNS is enabled in Audit account, and also in every account. For which events, logs, non-compliant services I will receive sns notifications, and frequency?
  7. VPC Flow logs can publish to Cloudwatch logs or s3. Could I use the existing CW logs from management account, or s3 buckets from Log Archive, or I should create new ones?
  8. I there any way to centralized logs for vpc flow or any logs from any service to Log Archive account? and try to obtain a centralized view?
  9. Apart from email of Audit account, could I use another email as sns notification?

Thanks a lot.

Orlando
asked 7 months ago107 views
No Answers

You are not logged in. Log in to post an answer.

A good answer clearly answers the question and provides constructive feedback and encourages professional growth in the question asker.

Guidelines for Answering Questions