Logging and monitoring

Create a Metric Alarm and Filter for AWS Management Console authentication failures

Risk Level

Informational (4)

Platform(s)
Compliance Frameworks

Description

Real-time monitoring of API calls can be achieved by directing CloudTrail Logs to CloudWatch Logs and establishing corresponding metric filters and alarms. Monitoring failed console logins may decrease lead time to detect an attempt to brute force a credential, which may provide an indicator, such as source IP, that can be used in other event correlation.
  • Recommended Mitigation

    It is recommended that a metric filter and alarm be established for failed console authentication attempts.