Ensure a Log Metric Filter and Alarm Exist for Management Console Sign-In Without MFA in AWS
Real-time monitoring of API calls can be achieved by directing CloudTrail Logs to CloudWatch Logs and establishing corresponding metric filters and alarms. It is recommended that a metric filter and alarm be established for console logins that are not protected by multi-factor authentication (MFA). Send results via Email.
icon
Breakdown
  1. Ensure a Log Metric Filter and Alarm Exist for Management Console Sign-In Without MFA.
  2. Send results via Email. This result step can be changed from Email to Slack, Microsoft Teams or Discord.