Logging and monitoring

CloudWatch alarms not monitoring security groups configuration

Description

AWS CloudWatch alarms feature allows to watch metrics and receive notifications when metrics fall outside the settings you configured. We have identified that the cloud account ""{CloudAccount}"" is not configured with CloudWatch metrics to monitor security groups configuration.
  • Recommended Mitigation

    Ensure cloudwatch metric is set to monitor security groups configuration. more details can be found in <a href="https://docs.aws.amazon.com/awscloudtrail/latest/userguide/send-cloudtrail-events-to-cloudwatch-logs.html" target="_blank" rel="noopener noreferrer">https://docs.aws.amazon.com/awscloudtrail/latest/userguide/send-cloudtrail-events-to-cloudwatch-logs.html</a>