Logging and monitoring

Create a Metric Alarm and Filter for S3 policy changes


Real-time monitoring of API calls can be achieved by directing CloudTrail Logs to CloudWatch and establishing corresponding metric filters and alarms. No such filter or alarm was detected for changes to S3 bucket policies. Monitoring changes to S3 bucket policies will make it easier to detect and rectify permissive policies.