Logs 2 Flashcards

1
Q

Subscription Filters

What is a Subscription Filter?

A

Set per Log Group, set filter criteria, destination

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Subscription Filters

Can you subscribe a destination to a Subscription Filter cross-account?

A

Yes for OpenSearch & Kinesis, no for Lambda

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Subscription Filters

Is delivery to Kinesis real-time?

important

A

Yes, other than Kinesis Data Streams, which has it’s own internal delay.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Subscription Filters

Is delivery to Lambda real-time?

important

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Subscription Filters

Best Practice for cross-account log aggregation?

A

All accounts use Subscription Filter to common Kinesis Data Stream, which loads into a warehouse

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Log Security

How can applications redact certain things in CWL?

A

Data Protection Policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Log Security

Where do you set DPPs?

A

On a Log Group

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Log Security

What happens when a DPP finds something bad in a log?

A

Can redact it or send an audit message elsewhere

How well did you know this?
1
Not at all
2
3
4
5
Perfectly