AWS Auth Failure

Ensures that a log metric filter and alarm exists for AWS management console authentication failures.

AWS Config Change

Ensures that a log metric filter and alarm exists for AWS Config configuration changes.

Alarm for UnAuthorized API calls

Ensures that a log metric filter and alarm exists for unauthorized API calls.

CMKs Deletion/Disable

Ensures that a log metric filter and alarm exists for disabling or scheduled deletion of customer created CMKs.

CloudTrail Config Change

Ensures that a log metric filter and alarm exists for CloudTrail Config Changes.

IAM Policy Change

Ensures that a log metric filter and alarm exists for IAM Policy changes.

MFA Console SignIn

Ensures that a log metric filter and alarm exists for management console sign-in without mutlifactor authentication.

NACL Change

Ensures that a log metric filter and alarm exists for changes in Network Access Control List.

Network Gateway Change

Ensures that a log metric filter and alarm exists for changes to Network Gateways.

Root Account Alarm

Ensures that a log metric filter and alarm exists for when there root access occurs.

Route Table Change

Ensures that a log metric filter and alarm exists for when there are changes in the route table.

S3 Policy Change

Ensures that a log metric filter and alarm exists for when there are changes in S3 Bucket policies.

Security Group Change

Ensures that a log metric filter and alarm exists for when there are changes in security groups.

VPC Change

Ensures that a log metric filter and alarm exists for when there are VPC changes.