High GuardDuty Regional

GuardDuty EKS Audit Log Monitoring should be enabled

FSBP

Description

Confirms that GuardDuty EKS Audit Log Monitoring is enabled across all accounts. This feature analyzes Kubernetes audit logs to detect suspicious activity in EKS clusters.


Remediation

To enable GuardDuty EKS Audit Log Monitoring, you need to configure the EKS protection settings in GuardDuty.

Steps

  1. Navigate to the Amazon GuardDuty console
  2. Go to 'Settings' in the left navigation
  3. Select 'EKS Protection'
  4. Enable 'EKS Audit Log Monitoring'
  5. Configure the monitoring settings as needed
  6. Save the configuration
  7. Verify that EKS audit log monitoring is active

Compliance

FSBP