Logging and monitoring

Create a Metric Alarm and Filter for AWS Organizations changes

Risk Level

Informational (4)



Real-time monitoring of API calls can be achieved by directing CloudTrail Logs to CloudWatch Logs and establishing corresponding metric filters and alarms. Monitoring AWS Organizations changes can help you prevent any unwanted, accidental or intentional modifications that may lead to unauthorized access or other security breaches. This monitoring technique helps you to ensure that any unexpected changes performed within your AWS Organizations can be investigated and any unwanted changes can be rolled back.
  • Recommended Mitigation

    It is recommended that a metric filter and alarm be established for AWS Organizations changes made in the master AWS Account.