Logging and monitoring

Log monitoring is not set up for Management Console sign-in without MFA

Description

Log Service is a real-time data logging service that supports collection, consumption, shipping, search, and analysis of logs. It was detected that log monitoring and alarm are not set up for management console sign-in without MFA. Monitoring for single-factor console logins will increase visibility into accounts that are not protected by MFA.
  • Recommended Mitigation

    It is recommended to set up an alarm in the central project, that will alert on management console sign-in without MFA. The suggested query is written in this alert's query. For information about alert configuring: <a href="https://www.alibabacloud.com/help/en/log-service/latest/configure-an-alert-in-log-service" target="_blank" rel="noopener noreferrer">https://www.alibabacloud.com/help/en/log-service/latest/configure-an-alert-in-log-service</a>