Medium
Connect
Regional
Amazon Connect instances should have CloudWatch logging enabled
FSBP
Description
Confirms that Amazon Connect instances store flow logs in a CloudWatch log group. Flow logs provide real-time details about events in Connect flows, aiding in error analysis, operational monitoring, and security alerting.
Remediation
Enable CloudWatch logging for your Amazon Connect instances to ensure flow logs are generated and stored.
Steps
- Navigate to the Amazon Connect console
- Select the Connect instance that needs logging enabled
- Go to the 'Data streaming' or 'Logging' section
- Enable 'Contact flow logs' or 'Flow logs'
- Configure the CloudWatch log group destination
- Set the appropriate log level and retention period
- Save the configuration
- Verify that flow logs are being generated in CloudWatch
Compliance
FSBP