< ciso
brief />
Tag Banner

All news with #log management tag

48 articles

Cloudflare Launches Unified Observability Platform

πŸ“Š Cloudflare announced eight major updates to unify logs, traces, analytics, alerts, dashboards, and export capabilities into a single observability platform with simpler pricing. The release combines Workers Observability and Log Explorer into a new Logs home, introduces Cloudflare Traces in open beta, and provides a unified SQL API and native Workers binding for querying telemetry. Alerts, Custom Dashboards, Logpush availability on self-serve plans, and usage-based export/transformer pricing complete the rollout.
read more β†’

Amazon Connect Customer adds APIs for custom metrics

πŸ“ˆ Amazon Connect Customer now supports programmatic creation, management, and search of custom metrics through seven new API operations. These include CreateMetric, DeleteMetric, DescribeMetric, ListMetrics, SearchMetrics, UpdateMetricContent, and UpdateMetricMetadata. Changes are logged in AWS CloudTrail and the feature is available in all Regions where Amazon Connect Customer is offered.
read more β†’

CloudWatch agent adds native journald log support

πŸ“£ The Amazon CloudWatch agent now supports reading systemd journal (journald) logs directly from Linux instances and sending them to Amazon CloudWatch Logs without writing files to disk. This native integration preserves journald structured metadata such as unit, priority, and process information. You can filter by systemd unit, priority, and journal fields, apply regex filters to reduce noise and control costs, and the feature is available in all AWS Commercial and GovCloud(US) regions. Update to the latest CloudWatch agent and add a journald section to your configuration to enable this functionality.
read more β†’

CloudWatch Centralization Adds Tag Propagation

πŸ”” Amazon CloudWatch Centralization now copies log group tags from source accounts to destination log groups created by centralization rules. Tag propagation preserves cost, ownership, and compliance tags so teams can scope access and report spend centrally. The feature syncs tags based on propagation behavior chosen in the centralization rule and is available in all Regions where CloudWatch Centralization is offered.
read more β†’

CloudWatch adds GeoIP, RDS and XML log parsers

πŸ”§ Amazon CloudWatch pipelines now includes three new processors: an Amazon RDS log parser, an XML parser, and a GeoIP enrichment processor. These processors parse and enrich logs as they are ingested, turning RDS Aurora audit and error logs into structured fields, converting XML strings into JSON, and adding geographic context to IP addresses. They are available at no extra charge where CloudWatch pipelines is GA; standard ingestion and storage rates still apply.
read more β†’

Amazon MSK adds Authorizer Log Delivery for clusters

πŸ”’ Amazon Managed Streaming for Apache Kafka (MSK) now supports Authorizer Log Delivery for Provisioned clusters, including Standard and Express brokers, at no additional cost. This feature captures denied authorization requests with client IP and attempted API, helping identify client authorization issues and satisfy security requirements. Logs can be delivered to Amazon CloudWatch Logs, Amazon S3, or Amazon Data Firehose, and can be enabled via the MSK console or AWS CLI. Authorizer Log Delivery is available for new and existing Provisioned clusters in all supported Regions except the AWS European Sovereign Cloud (eusc-de-east-1).
read more β†’

RDS SQL Server Audit Logs Published to CloudWatch

πŸ“£ Amazon RDS for SQL Server now supports publishing native SQL Server Audit logs to CloudWatch. You can configure audits and audit specifications as on-premises and publish logs to S3, CloudWatch, or both. When both destinations are enabled, publication completes only after successful upload to both services, and CloudWatch enables real-time log analysis. The feature is available in all AWS Commercial and GovCloud (US) Regions where RDS for SQL Server is offered.
read more β†’

NCSC urges manufacturers to enable forensic observability

πŸ”’ The UK’s National Cyber Security Centre (NCSC) has urged device manufacturers to make forensic evidence collection easier after compromises. Chris A, NCSC technical director, warned that firewalls, VPN gateways and other network devices are increasingly targeted, and stressed that built-in telemetry, logging, memory and data-at-rest collection, and software transparency are crucial. He dispelled myths that observability aids attackers or is too difficult, and called on vendors and buyers to prioritize these capabilities.
read more β†’

CloudWatch Logs Adds ALB Vended Logs Support

πŸ“£ Amazon CloudWatch Logs now supports vended Application Load Balancer (ALB) logs to improve observability and simplify debugging of network traffic patterns. You can analyze ALB access, connection, and health check logs directly in CloudWatch to gain insights into client connections, traffic distribution, and target health. CloudWatch telemetry enablement rules allow automatic configuration of logging for existing and new ALBs across organizations, accounts, or specific resources to ensure consistent monitoring coverage.
read more β†’

CloudWatch Logs Insights adds 25 query commands

πŸ” Amazon CloudWatch Logs Insights now supports 25 new commands and functions to enhance log querying, transformation, correlation, and analysis. The additions include type conversion and encoding, date/time, string, JSON inspection, statistical, sessionization, sequencing, null-handling, comparison, join, and lookup enrichment capabilities. These features are available today in all commercial AWS Regions and extend common tasks such as outlier detection, time-window comparisons, enrichment with lookup data, and handling of nulls in time-series analysis. See the CloudWatch Logs documentation for details.
read more β†’

Amazon CloudWatch adds intelligent log tiering

πŸ” Amazon CloudWatch Logs now offers intelligent storage tiering across three tiers β€” Standard, Infrequent Access, and Archive Instant Access β€” automatically classifying log data based on access patterns. This feature lets you retain high-volume verbose logs natively in CloudWatch at lower cost without operational overhead, while preserving the same query experience regardless of tier. Data not accessed for 30 days moves to Infrequent Access and for 90 days to Archive Instant Access; accessing older data promotes it back to Standard for 30 days. Intelligent-tiering is available in all AWS commercial regions except Bahrain and UAE and can be enabled at the account level via Console, SDKs, or CLI.
read more β†’

Amazon CloudWatch adds lookup processor for log enrichment

πŸ“Œ Amazon CloudWatch now offers a lookup processor that enriches log events by matching log fields against uploaded CSV lookup tables within CloudWatch Pipelines. You can map reference dataβ€”such as IP-to-team, user IDs, or product codesβ€”to automatically add metadata at ingestion, improving queries, dashboards, and alarms without external processing. The feature is available in all commercial AWS regions that support CloudWatch Pipelines and is configurable via the Console, CLI, or SDKs.
read more β†’

Amazon OpenSearch launches log analytics engine

πŸ” Amazon OpenSearch Service introduces a new engine optimized for log analytics that combines faster analytical queries with full-text search. The engine delivers up to 4x better price-performance on internal benchmarks, up to 70% lower storage using columnar storage, 2x higher ingestion throughput, and 2x faster analytical queries. It supports OpenSearch 3.5+, PPL and SQL queries, JDBC/ODBC drivers, and mixed full-text plus analytical predicates. The capability is available across 12 global AWS regions with no additional engine charges.
read more β†’

CloudWatch Logs adds resource tag enrichment

πŸ” Amazon CloudWatch Logs now enriches log events with AWS resource tags at ingestion, enabling filtering, searching, and analysis by metadata such as team ownership, environment, cost center, or application name without changing logging instrumentation. Tags are applied at ingestion so you can use them immediately in log queries to scope analysis and incident investigations. The feature is available in all commercial AWS Regions except UAE, Bahrain, and Israel (Tel Aviv). Enable resource tags on telemetry in Amazon CloudWatch Settings, via the AWS CLI, or SDKs; tag enrichment is provided at no extra cost.
read more β†’

Amazon S3 delivers server access logs to CloudWatch

πŸ“£ Amazon S3 now supports delivering server access logs to Amazon CloudWatch Logs, enabling instant querying, alarms, cross-account and cross-Region aggregation, and AWS KMS encryption for access log data. You can also mirror logs to Amazon S3 Tables in Apache Iceberg format at no additional storage cost. These delivery options complement existing free delivery to S3 buckets and provide more flexibility for monitoring and analysis.
read more β†’

Amazon CloudWatch adds managed syslog ingestion

πŸ“₯ Amazon CloudWatch Logs now offers managed syslog ingestion, allowing firewalls, routers, switches, and Linux servers to send syslog messages directly to CloudWatch without agents. It accepts TCP, TCP+TLS, and UDP to a VPC endpoint and supports RFC 5424, RFC 3164, and Cisco FTD/ASA formats. CloudWatch automatically parses messages to extract fields like facility, severity, hostname, and application, enabling immediate querying via Logs Analytics. The feature is available in all commercial AWS Regions except UAE, Bahrain, and Israel.
read more β†’

Amazon CloudWatch Adds Log Analytics Console

πŸ› οΈ Amazon CloudWatch introduces Log Analytics, a unified console that combines CloudWatch Logs Insights, Live Tail, and Contributor Insights for integrated log querying, real-time streaming, and contributor identification. Users can run multiple queries in tabs, leverage patterns, saved queries with parameters, facets, natural language query generation, and visualizations. Live Tail and Contributor Insights are accessible within Log Analytics, which is the default experience, while opt-out users retain separate access to each feature. The capability is available in all commercial AWS Regions and uses existing pricing for Logs Insights queries, Live Tail, and Contributor Insights.
read more β†’

OMB M-26-14: From Data Hoarding to Active Defense

πŸ” The OMB Memo M-26-14 ends compliance-driven data hoarding and mandates a risk-based, machine-speed logging approach. It requires six months of logs to be hot and searchable and one year retrievable, expands visibility to IoT/OT, and emphasizes continuous event monitoring and AI-driven detection. Legacy SIEMs struggle to meet these goals; Palo Alto Networks positions Cortex XSIAM as a FedRAMP-certified solution built for index-free, AI-enabled, cross-domain threat hunting.
read more β†’

Attack Techniques Targeting Cloud Logging Services

πŸ” Cloud logging services like AWS CloudTrail and Google Cloud Logging offer essential visibility into cloud activity but are also high-value targets for attackers. This article examines two primary attack goalsβ€”defense evasion and establishing continuous visibilityβ€”and demonstrates methods attackers use to disrupt or exfiltrate logs. It outlines practical attack techniques such as stopping logging, deleting storage or routers, abusing encryption keys, and log poisoning, and highlights detection and mitigation approaches.
read more β†’

CloudWatch Logs Insights adds 23 query commands

πŸ” Amazon CloudWatch Logs Insights now supports 23 new query commands and functions to enhance log querying, parsing, transformation, and analysis. The update adds hash functions (md5, sha256), string and conversion utilities (strcontains, split, toNumber, toInt), IP utilities (ipv4ToNumber, isPrivateIP), analytics functions (rate, count_over_time, histogram), and expanded parsing capabilities (parse CSV, XML, multi). Queries can now use β€œlimit any N” and up to 10 stats commands, and these features are available in all commercial AWS Regions.
read more β†’