Medium SSM Regional

SSM Automation should have CloudWatch logging enabled

FSBP

Description

Verifies that CloudWatch logging is enabled for AWS Systems Manager Automation.


Remediation

To enable CloudWatch logging for SSM Automation, configure the service setting to send automation script output to CloudWatch Logs.

Steps

  1. Open the AWS Systems Manager console at https://console.aws.amazon.com/systems-manager/.
  2. In the navigation pane, choose Automation.
  3. Choose the Preferences tab, and then choose Edit.
  4. Select the check box next to Send output to CloudWatch Logs.
  5. For CloudWatch Logs log group, select or create a log group.
  6. Choose Save.

Compliance

FSBP