Medium
SSM
Regional
SSM Automation should have CloudWatch logging enabled
FSBP
Description
Verifies that CloudWatch logging is enabled for AWS Systems Manager Automation.
Remediation
To enable CloudWatch logging for SSM Automation, configure the service setting to send automation script output to CloudWatch Logs.
Steps
- Open the AWS Systems Manager console at https://console.aws.amazon.com/systems-manager/.
- In the navigation pane, choose Automation.
- Choose the Preferences tab, and then choose Edit.
- Select the check box next to Send output to CloudWatch Logs.
- For CloudWatch Logs log group, select or create a log group.
- Choose Save.
Compliance
FSBP