< ciso
brief />
Tag Banner

All news with #log management tag

45 articles

CloudWatch Centralization Adds Tag Propagation

๐Ÿ”” Amazon CloudWatch Centralization now copies log group tags from source accounts to destination log groups created by centralization rules. Tag propagation preserves cost, ownership, and compliance tags so teams can scope access and report spend centrally. The feature syncs tags based on propagation behavior chosen in the centralization rule and is available in all Regions where CloudWatch Centralization is offered.
read more โ†’

CloudWatch adds GeoIP, RDS and XML log parsers

๐Ÿ”ง Amazon CloudWatch pipelines now includes three new processors: an Amazon RDS log parser, an XML parser, and a GeoIP enrichment processor. These processors parse and enrich logs as they are ingested, turning RDS Aurora audit and error logs into structured fields, converting XML strings into JSON, and adding geographic context to IP addresses. They are available at no extra charge where CloudWatch pipelines is GA; standard ingestion and storage rates still apply.
read more โ†’

Amazon MSK adds Authorizer Log Delivery for clusters

๐Ÿ”’ Amazon Managed Streaming for Apache Kafka (MSK) now supports Authorizer Log Delivery for Provisioned clusters, including Standard and Express brokers, at no additional cost. This feature captures denied authorization requests with client IP and attempted API, helping identify client authorization issues and satisfy security requirements. Logs can be delivered to Amazon CloudWatch Logs, Amazon S3, or Amazon Data Firehose, and can be enabled via the MSK console or AWS CLI. Authorizer Log Delivery is available for new and existing Provisioned clusters in all supported Regions except the AWS European Sovereign Cloud (eusc-de-east-1).
read more โ†’

RDS SQL Server Audit Logs Published to CloudWatch

๐Ÿ“ฃ Amazon RDS for SQL Server now supports publishing native SQL Server Audit logs to CloudWatch. You can configure audits and audit specifications as on-premises and publish logs to S3, CloudWatch, or both. When both destinations are enabled, publication completes only after successful upload to both services, and CloudWatch enables real-time log analysis. The feature is available in all AWS Commercial and GovCloud (US) Regions where RDS for SQL Server is offered.
read more โ†’

NCSC urges manufacturers to enable forensic observability

๐Ÿ”’ The UKโ€™s National Cyber Security Centre (NCSC) has urged device manufacturers to make forensic evidence collection easier after compromises. Chris A, NCSC technical director, warned that firewalls, VPN gateways and other network devices are increasingly targeted, and stressed that built-in telemetry, logging, memory and data-at-rest collection, and software transparency are crucial. He dispelled myths that observability aids attackers or is too difficult, and called on vendors and buyers to prioritize these capabilities.
read more โ†’

CloudWatch Logs Adds ALB Vended Logs Support

๐Ÿ“ฃ Amazon CloudWatch Logs now supports vended Application Load Balancer (ALB) logs to improve observability and simplify debugging of network traffic patterns. You can analyze ALB access, connection, and health check logs directly in CloudWatch to gain insights into client connections, traffic distribution, and target health. CloudWatch telemetry enablement rules allow automatic configuration of logging for existing and new ALBs across organizations, accounts, or specific resources to ensure consistent monitoring coverage.
read more โ†’

CloudWatch Logs Insights adds 25 query commands

๐Ÿ” Amazon CloudWatch Logs Insights now supports 25 new commands and functions to enhance log querying, transformation, correlation, and analysis. The additions include type conversion and encoding, date/time, string, JSON inspection, statistical, sessionization, sequencing, null-handling, comparison, join, and lookup enrichment capabilities. These features are available today in all commercial AWS Regions and extend common tasks such as outlier detection, time-window comparisons, enrichment with lookup data, and handling of nulls in time-series analysis. See the CloudWatch Logs documentation for details.
read more โ†’

Amazon CloudWatch adds intelligent log tiering

๐Ÿ” Amazon CloudWatch Logs now offers intelligent storage tiering across three tiers โ€” Standard, Infrequent Access, and Archive Instant Access โ€” automatically classifying log data based on access patterns. This feature lets you retain high-volume verbose logs natively in CloudWatch at lower cost without operational overhead, while preserving the same query experience regardless of tier. Data not accessed for 30 days moves to Infrequent Access and for 90 days to Archive Instant Access; accessing older data promotes it back to Standard for 30 days. Intelligent-tiering is available in all AWS commercial regions except Bahrain and UAE and can be enabled at the account level via Console, SDKs, or CLI.
read more โ†’

Amazon CloudWatch adds lookup processor for log enrichment

๐Ÿ“Œ Amazon CloudWatch now offers a lookup processor that enriches log events by matching log fields against uploaded CSV lookup tables within CloudWatch Pipelines. You can map reference dataโ€”such as IP-to-team, user IDs, or product codesโ€”to automatically add metadata at ingestion, improving queries, dashboards, and alarms without external processing. The feature is available in all commercial AWS regions that support CloudWatch Pipelines and is configurable via the Console, CLI, or SDKs.
read more โ†’

Amazon OpenSearch launches log analytics engine

๐Ÿ” Amazon OpenSearch Service introduces a new engine optimized for log analytics that combines faster analytical queries with full-text search. The engine delivers up to 4x better price-performance on internal benchmarks, up to 70% lower storage using columnar storage, 2x higher ingestion throughput, and 2x faster analytical queries. It supports OpenSearch 3.5+, PPL and SQL queries, JDBC/ODBC drivers, and mixed full-text plus analytical predicates. The capability is available across 12 global AWS regions with no additional engine charges.
read more โ†’

CloudWatch Logs adds resource tag enrichment

๐Ÿ” Amazon CloudWatch Logs now enriches log events with AWS resource tags at ingestion, enabling filtering, searching, and analysis by metadata such as team ownership, environment, cost center, or application name without changing logging instrumentation. Tags are applied at ingestion so you can use them immediately in log queries to scope analysis and incident investigations. The feature is available in all commercial AWS Regions except UAE, Bahrain, and Israel (Tel Aviv). Enable resource tags on telemetry in Amazon CloudWatch Settings, via the AWS CLI, or SDKs; tag enrichment is provided at no extra cost.
read more โ†’

Amazon S3 delivers server access logs to CloudWatch

๐Ÿ“ฃ Amazon S3 now supports delivering server access logs to Amazon CloudWatch Logs, enabling instant querying, alarms, cross-account and cross-Region aggregation, and AWS KMS encryption for access log data. You can also mirror logs to Amazon S3 Tables in Apache Iceberg format at no additional storage cost. These delivery options complement existing free delivery to S3 buckets and provide more flexibility for monitoring and analysis.
read more โ†’

Amazon CloudWatch adds managed syslog ingestion

๐Ÿ“ฅ Amazon CloudWatch Logs now offers managed syslog ingestion, allowing firewalls, routers, switches, and Linux servers to send syslog messages directly to CloudWatch without agents. It accepts TCP, TCP+TLS, and UDP to a VPC endpoint and supports RFC 5424, RFC 3164, and Cisco FTD/ASA formats. CloudWatch automatically parses messages to extract fields like facility, severity, hostname, and application, enabling immediate querying via Logs Analytics. The feature is available in all commercial AWS Regions except UAE, Bahrain, and Israel.
read more โ†’

Amazon CloudWatch Adds Log Analytics Console

๐Ÿ› ๏ธ Amazon CloudWatch introduces Log Analytics, a unified console that combines CloudWatch Logs Insights, Live Tail, and Contributor Insights for integrated log querying, real-time streaming, and contributor identification. Users can run multiple queries in tabs, leverage patterns, saved queries with parameters, facets, natural language query generation, and visualizations. Live Tail and Contributor Insights are accessible within Log Analytics, which is the default experience, while opt-out users retain separate access to each feature. The capability is available in all commercial AWS Regions and uses existing pricing for Logs Insights queries, Live Tail, and Contributor Insights.
read more โ†’

OMB M-26-14: From Data Hoarding to Active Defense

๐Ÿ” The OMB Memo M-26-14 ends compliance-driven data hoarding and mandates a risk-based, machine-speed logging approach. It requires six months of logs to be hot and searchable and one year retrievable, expands visibility to IoT/OT, and emphasizes continuous event monitoring and AI-driven detection. Legacy SIEMs struggle to meet these goals; Palo Alto Networks positions Cortex XSIAM as a FedRAMP-certified solution built for index-free, AI-enabled, cross-domain threat hunting.
read more โ†’

Attack Techniques Targeting Cloud Logging Services

๐Ÿ” Cloud logging services like AWS CloudTrail and Google Cloud Logging offer essential visibility into cloud activity but are also high-value targets for attackers. This article examines two primary attack goalsโ€”defense evasion and establishing continuous visibilityโ€”and demonstrates methods attackers use to disrupt or exfiltrate logs. It outlines practical attack techniques such as stopping logging, deleting storage or routers, abusing encryption keys, and log poisoning, and highlights detection and mitigation approaches.
read more โ†’

CloudWatch Logs Insights adds 23 query commands

๐Ÿ” Amazon CloudWatch Logs Insights now supports 23 new query commands and functions to enhance log querying, parsing, transformation, and analysis. The update adds hash functions (md5, sha256), string and conversion utilities (strcontains, split, toNumber, toInt), IP utilities (ipv4ToNumber, isPrivateIP), analytics functions (rate, count_over_time, histogram), and expanded parsing capabilities (parse CSV, XML, multi). Queries can now use โ€œlimit any Nโ€ and up to 10 stats commands, and these features are available in all commercial AWS Regions.
read more โ†’

Amazon EKS Capabilities add CloudWatch Vended Logs

๐ŸŸฃ Amazon EKS Capabilities can now be configured as log delivery sources using Amazon CloudWatch Vended Logs to capture logs from managed controllers such as Argo CD, AWS Controllers for Kubernetes (ACK), and kro. Customers can enable delivery via CloudWatch APIs or the AWS Console and send logs to CloudWatch Logs, Amazon S3, or Amazon Kinesis Data Firehose. The feature is available in all Regions that support EKS Capabilities and incurs standard CloudWatch Vended Logs pricing with no additional EKS charge.
read more โ†’

AWS Shield Advanced adds DDoS attack flow logs

๐Ÿ“ก AWS Shield Advanced now provides DDoS attack flow logs that deliver packet-level visibility into traffic targeting Shield-protected resources. The logs capture source and destination IPs, ports, protocols, packet and byte counts, and source country details, and are published every five minutes during active attacks. Log data can be delivered to Amazon S3, Amazon CloudWatch Logs, or Amazon Data Firehose for forensic analysis, threat intelligence, and compliance. To use the feature, resources must be protected by Shield Advanced and log delivery must be configured; the feature is available in all regions where Shield Advanced operates.
read more โ†’

Cloudflareโ€™s Unified Data Platform: Town Lake

๐Ÿ“Š Cloudflare built Town Lake, a lakehouse-style unified data analytics platform, and Skipper, an AI data agent, to make its vast telemetry and logs queryable and auditable. Town Lake combines Trino, Iceberg on R2, a metadata catalog, PII scanning, access control, and ELT tooling to provide fresh, accurate, and governed data. Skipper lets non-SQL users ask natural-language questions, produce correct SQL-backed answers, and create shareable charts and dashboards.
read more โ†’