AWS Control Tower - SNS notifications

0

Hi Team.

I have installed AWS Control Tower, and I see that sns topics were enabled on Audit Account and every account members. Also I see lambda (named notification forwarder) as subscriptor of sns topic on every account. on the other hand, I see AWS Config was enabled on every account, and it has delivery method to S3 and SNS topic from the Audit Account.

So, I dont understand why there is a sns on every account, if the AWS Config has configured another SNS topic from Audit Account, or when is used sns local and sns audit account?

Thank you.

Orlando
已提問 7 個月前檢視次數 228 次
1 個回答
1

Hi Orlando,

The SNS topic in every account has a destination of lambda forwarder, which forwards the notification to the SNS topic in the Audit account which sends an email to the Audit account email ID. Think of it as a notification collection mechanism from member accounts. Also note that the management account does not have an SNS topic created for control tower.

Karn C
已回答 7 個月前
  • Can you please clarify why the management account does not have the SNS topic?

您尚未登入。 登入 去張貼答案。

一個好的回答可以清楚地回答問題並提供建設性的意見回饋,同時有助於提問者的專業成長。

回答問題指南