Medium
Elasticsearch
Regional
Elasticsearch domain error logging to CloudWatch Logs should be enabled
NISTISO 27001
Description
This check ensures that Elasticsearch domains have error logging to CloudWatch Logs enabled for better monitoring and troubleshooting.
Remediation
To enable error logging to CloudWatch Logs for an Elasticsearch domain, follow these steps:
Steps
- Open the Amazon Elasticsearch Service console at https://console.aws.amazon.com/es/.
- Choose the domain that you want to modify.
- In the navigation pane, under Domain configuration, choose Log Publishing Options.
- For Error logs, select the Enabled checkbox.
- Choose a CloudWatch Logs log group and specify the IAM role to use.
- Choose Save changes.
Compliance
NISTISO 27001