我设置了SNS通知,在IAM策略发生变化时向我发送电子邮件。发生更改时,CloudTrail会将日志发送到CloudWatch,从而触发附加到SNS主题的警报。在此link的更多详细信息。发生IAM更改时发送SNS通知
下面是我通过邮件得到一个例子:
Alarm Details:
- Name: PolicyAlarm
- Description: This alarm is to monitor IAM Changes
- State Change: INSUFFICIENT_DATA -> ALARM
- Reason for State Change: Threshold Crossed: 1 datapoint [1.0 (31/08/17 09:15:00)] was greater than or equal to the threshold (1.0).
- Timestamp: Thursday 31 August, 2017 09:20:39 UTC
- AWS Account: 00011100000
Threshold:
- The alarm is in the ALARM state when the metric is GreaterThanOrEqualToThreshold 1.0 for 300 seconds.
这里唯一的相关信息是AWS Account ID
。有没有办法可以包含更改?谁做的,何时何地?或者可能从"eventName"
这样的Cloudwatch日志中发送很少的信息?
评估AWS Config。它会给你当前的配置。编写一个逻辑来确定更改。关于谁进行了更改,您需要查看CloudTrail日志。 –