< ciso
brief />
Tag Banner

All news with #aws tag

2926 articles · page 62 of 147

CloudWatch Logs Insights Adds JOIN and Sub-query Support

🔎 Amazon has added JOIN and sub-query commands to CloudWatch Logs Insights, enabling queries that span multiple log groups and correlate data from different sources. The new capabilities remove the need to run separate queries and manually merge results, accelerating troubleshooting and investigations. Typical uses include correlating application and infrastructure errors, analyzing security events across services, and tracking user sessions across distributed systems. The features are available today in all commercial AWS Regions.
read more →

Cloning AWS CloudHSM Clusters Across Regions Securely

🛡️ This AWS Security Blog post demonstrates how to clone an AWS CloudHSM cluster across Regions using the copy-backup-to-region workflow and Client SDK 5 (recommended version 5.17 or later). It walks through creating and initializing a source cluster, generating a backup, copying that backup to a destination Region, and launching a new cluster from the copied backup, including certificate transfer and security group adjustments. The guide emphasizes that non-exportable keys can only be synchronized to cloned clusters, that users and passwords must be maintained manually after the initial backup, and that Client SDK 3 reached end-of-support on January 1, 2025, so migration to SDK 5 is required.
read more →

Amazon MSK Replicator: Enhanced Consumer Offset Sync

🔁 Amazon has added enhanced consumer offset synchronization to MSK Replicator, improving bidirectional Kafka replication so consumer applications resume from the correct position when moved across clusters. This lets teams move producers and consumers independently, in any order, without risking data loss or duplicate processing. Previously, offsets synchronized only when producers and consumers ran on the same cluster, which required careful migration sequencing. The feature can be enabled via the AWS Console, AWS CLI, or AWS CloudFormation and is available in all Regions where MSK Replicator is offered.
read more →

Amazon MSK Replicator adds end-to-end replication logs

🔍 Amazon MSK Replicator now delivers replicator logs that provide end-to-end visibility into replication health. The logs surface critical replication events, client errors, and steady-state activity, and include prescriptive guidance to help operators resolve common issues more quickly. Common problems called out in log entries include insufficient permissions on source topics, partition quota exhaustion on target clusters, and records exceeding size limits. You can enable log delivery when creating or updating a Replicator via the AWS Console, AWS CLI, or AWS CloudFormation and forward logs to Amazon CloudWatch, Amazon S3, or Amazon Data Firehose.
read more →

Amazon MSK Replicator Adds External Kafka Cluster Support

🔁 Amazon Web Services announced that Amazon MSK Replicator now supports replicating data from external Apache Kafka clusters—including on‑premises, self‑managed on AWS, or third‑party clouds—into MSK Express brokers. This capability simplifies workload migration, enables MSK Express clusters to act as failover or backup targets for disaster recovery, and supports hybrid and multi‑cloud data distribution. MSK Replicator preserves original topic names, prevents infinite replication loops, and synchronizes consumer group offsets bidirectionally to let producers and consumers move independently without data loss.
read more →

Amazon S3 Express One Zone Supports S3 Inventory Reports

📦 Amazon announced that S3 Express One Zone, its high-performance storage class for latency-sensitive workloads, now supports S3 Inventory. Inventory provides a scheduled, asynchronous alternative to the synchronous List API, producing daily or weekly reports that include object metadata, encryption status, and storage class. You can configure reports via the AWS CLI, SDKs, or S3 API and choose CSV, ORC, or Parquet output, with delivery to a specified destination bucket.
read more →

Amazon Connect adds touchtone buffering for AI self-service

🤖 Amazon Connect now supports touchtone buffering to automatically pass caller context into AI-powered self-service sessions. When calls are initiated from websites, mobile apps, or links, contextual data such as customer IDs, session references, and campaign codes can be delivered at connect time. AI agents use this data to identify callers, understand intent, and act without requiring re-identification or repeated explanations.
read more →

AWS Transform Automates Landing Zone Setup for Migrations

🔧 AWS Transform now supports landing zone creation directly within migration workflows, enabling automated deployment of a secure, multi-account AWS environment tailored to migration requirements. By consolidating orchestration previously handled across AWS Control Tower, AWS Organizations, and AWS IAM, the feature accelerates migration readiness and removes a separate target-environment workstream. Customers can customize OU hierarchies, accounts, and SCPs, choose agent-managed deployment, or download Infrastructure as Code templates in CloudFormation, AWS CDK, or Landing Zone Accelerator formats. The capability is available across supported target regions.
read more →

AWS Managed Microsoft AD upgraded to 2016 functional level

🔒 AWS has automatically upgraded all AWS Managed Microsoft AD directories to the Windows functional level 2016, effective Apr 20, 2026. The update delivers enhanced authentication and improved privileged access management and enables built-in LAPS to generate unique, complex local administrator passwords stored securely in Active Directory. The upgrade is applied in all Regions where the service is available, except Middle East (UAE) and Middle East (Bahrain). See the AWS Directory Service Administration Guide for details.
read more →

AWS Managed Microsoft AD: Kerberos Encryption Logs

🔒 AWS Managed Microsoft AD can now forward Kerberos Encryption audit event logs (Event IDs 201–209) to Amazon CloudWatch Logs. These logs provide visibility into whether clients and services negotiate RC4 or AES encryption, helping you decide whether to upgrade clients for stronger protection or retain compatibility. Enable log forwarding from the directory's Network and Security tab in the Directory Service console. This feature is available in all AWS Regions offering the service except UAE and Bahrain.
read more →

AWS Adds High Memory U7i 8TB and 12TB in Singapore

🚀 AWS has launched EC2 High Memory U7i instances — u7i-8tb.112xlarge and u7i-12tb.224xlarge — in the Asia Pacific (Singapore) region. These 7th-generation instances use custom fourth-generation Intel Xeon Scalable (Sapphire Rapids) processors and provide 8TiB or 12TiB of DDR5 memory with 448 and 896 vCPUs respectively. They support up to 100 Gbps for Amazon EBS and network bandwidth and include ENA Express, targeting mission-critical in-memory databases such as SAP HANA, Oracle, and SQL Server.
read more →

Amazon SageMaker HyperPod Adds Flexible Instance Groups

🆕 Amazon SageMaker HyperPod now supports flexible instance groups, allowing multiple instance types and multiple subnets within a single instance group. Using a new InstanceRequirements parameter, HyperPod provisions the highest-priority instance type first and automatically falls back to lower-priority types when capacity is unavailable. The feature integrates with Karpenter autoscaling and can be created via the CreateCluster/UpdateCluster APIs, AWS CLI, or the Management Console.
read more →

AWS Neuron SDK 2.29 Released with Stable NKI expanded tools

🚀 AWS released Neuron SDK 2.29.0, promoting the Neuron Kernel Interface (NKI) to Stable (v0.3.0) and adding a Standard Library plus a CPU Simulator for local kernel development. The update introduces ISA-level features, DMA priority controls, and variable-length collectives, along with seven new experimental kernels and improvements to existing ones. NxD Inference and the vLLM Neuron Plugin receive vision-language optimizations. Neuron Explorer moves to Stable and is available on the VS Code marketplace.
read more →

Amazon ECR Pull-Through Cache Now Syncs OCI Referrers

🔁 Amazon Elastic Container Registry (Amazon ECR) now automatically discovers and caches OCI referrers — including image signatures, SBOMs, and attestations — from upstream registries for repositories configured with pull through cache. Previously, referrers had to be listed and fetched manually because ECR would not return or sync them for cached repositories. With this change, referrers API requests reach upstream and automatically cache related artifacts, enabling end-to-end signature verification, SBOM discovery, and attestation retrieval without client-side workarounds. The feature is available today in all Regions where Amazon ECR pull through cache is supported.
read more →

Amazon SageMaker HyperPod Adds On-Demand GPU Health Checks

🔍 Amazon SageMaker HyperPod now supports on-demand deep health checks for Amazon EKS and Slurm-orchestrated clusters. Administrators can run comprehensive GPU stress and connectivity tests on entire instance groups or specific instances, with progress and results visible at both group and instance levels via the SageMaker console and APIs. Instances under test are isolated from scheduling and are returned to service upon passing or, when paired with automatic node recovery, rebooted or replaced if they fail.
read more →

AWS Deadline Cloud launches AI troubleshooting assistant

🔎 AWS Deadline Cloud now includes an AI-powered troubleshooting assistant that analyzes failed render jobs to diagnose root causes and recommend fixes. The assistant examines logs and metrics for issues like missing assets, software errors, configuration mismatches, and resource constraints, drawing on a pre-trained knowledge base covering Deadline Cloud and popular DCC apps. It runs inside your AWS account via Amazon Bedrock and is available in all regions that support Deadline Cloud.
read more →

Configuration-Driven ETL to Convert Logs to OCSF at Scale

🔁 The AWS Professional Services team provides a configuration-driven ETL accelerator that converts custom security logs into OCSF v1.1 and writes OCSF-compliant Parquet files partitioned for use with Amazon Security Lake or other data lakes. The serverless-first solution uses S3, Lambda, DynamoDB, Step Functions and either AWS Glue or EMR Serverless, and ingests mapping and metadata CSVs to drive transformations. An open-source GitHub repository includes deployment artifacts, example mappings, and instructions to validate outputs and run historical loads.
read more →

Amazon Connect Flow Modules Now Work Across All Flows

🔁 Amazon Connect now supports using flow modules across all flow types, enabling reuse of common logic beyond inbound customer experiences. You can embed modules within other modules to build layered, maintainable processes—examples include sharing recent-transaction data in an agent whisper flow or composing credit-eligibility workflows that invoke score, income, and payment-history checks. This modular approach simplifies development and scaling. The capability is available in all AWS regions offering Amazon Connect.
read more →

Amazon Managed Grafana Adds Support for Grafana 12.4

📈 Amazon Managed Grafana now supports creating workspaces with Grafana 12.4. The release includes features from Grafana 11.0–12.4 such as queryless Drilldown apps, the Scenes rendering engine for improved dashboard performance, variables in transformations, a rebuilt table visualization with CSS cell styling and Actions buttons, and trendline transformations. Amazon CloudWatch plugin updates add PPL/SQL log querying, cross-account Metrics Insights, and log anomaly detection. Create workspaces via the AWS Console, SDK, or CLI.
read more →

AWS Clean Rooms Adds Configurable PySpark Properties

⚙️ AWS Clean Rooms now supports configurable Spark properties for PySpark analyses, allowing customers to tune memory overhead, task concurrency, and network timeouts on a per-job basis. This capability helps teams adapt resource allocation to specific performance and scale requirements, improving throughput and cost efficiency. For example, pharmaceutical researchers collaborating with healthcare partners can set tailored memory and concurrency settings for large real-world clinical datasets to optimize runtime and expenses.
read more →