For minimum AWS security logs onboarding, enable CloudTrail (all regions), AWS Config, VPC Flow Logs, and CloudWatch. Centralize logs, set appropriate retention, and secure access. This forms the baseline for visibility and compliance.
------------------------------
Rohit Sansiya
Project Engineer
Information Security Services (ISS-SANS)
Centre for Development of Advanced Computing(C-DAC), Hyderabad
Mobile: 8765232907
------------------------------
Original Message:
Sent: Apr 21, 2025 06:55:35 PM
From: Jayesh Dalmet
Subject: AWS Logging strategies - Minimum Requirements for Security Logs onboarding
The below logs need to be collected
Logs of all API calls made to AWS services.
Logs of S3 object-level operations and Lambda function invocations.
unusual API activity patterns.
Records of configuration changes to AWS resources.
logs of requests made to CloudFront distributions
Logs of requests made to S3 buckets.
Logs of requests sent to ELB, including client IP addresses and request paths.
Also, need to ensure that logs are retained for an appropriate period to meet compliance requirements
------------------------------
Jayesh Dalmet
Sr. Network Security Engineer - L4
NetApp
Original Message:
Sent: Feb 20, 2025 01:25:11 PM
From: Ewaldo S Hiras
Subject: AWS Logging strategies - Minimum Requirements for Security Logs onboarding
This depends on your threat model, but a good practical reference is available here: https://aws.amazon.com/blogs/security/logging-strategies-for-security-incident-response/
------------------------------
Ewaldo S Hiras
Independent Researcher
GGS
Original Message:
Sent: Sep 19, 2023 12:32:56 AM
From: Panagiotis Chavariotis
Subject: AWS Logging strategies - Minimum Requirements for Security Logs onboarding
Dear community,
Effective security incident response depends on adequate logging. If you have the proper logs and can query them, you can respond more rapidly and effectively to security events. If a security event occurs, you can use various log sources to validate what happened and understand the scope. Then, you can use the results of your analysis to take remediation actions.
Is there any document that outlines the minimum log requirements, that all services within an AWS account must send to the Security Operation Center?
Regards,
------------------------------
Panagiotis Chavariotis
------------------------------