Medium
Opensearch
Regional
OpenSearch domain error logging to CloudWatch Logs should be enabled
NISTISO 27001
Description
This check ensures that OpenSearch domains have error logging to CloudWatch Logs enabled for better monitoring and troubleshooting.
Remediation
To enable error logging to CloudWatch Logs for an OpenSearch domain, follow these steps:
Steps
- Open the Amazon OpenSearch Service console at https://console.aws.amazon.com/opensearch/.
- Choose the domain that you want to modify.
- In the navigation pane, under Cluster configuration, choose Log Publishing Options.
- For Error logs, select Enable to CloudWatch Logs.
- Choose Save changes.
Compliance
NISTISO 27001