Logs 2 Flashcards
Subscription Filters
What is a Subscription Filter?
Set per Log Group, set filter criteria, destination
Subscription Filters
Can you subscribe a destination to a Subscription Filter cross-account?
Yes for OpenSearch & Kinesis, no for Lambda
Subscription Filters
Is delivery to Kinesis real-time?
important
Yes, other than Kinesis Data Streams, which has it’s own internal delay.
Subscription Filters
Is delivery to Lambda real-time?
important
Yes
Subscription Filters
Best Practice for cross-account log aggregation?
All accounts use Subscription Filter to common Kinesis Data Stream, which loads into a warehouse
Log Security
How can applications redact certain things in CWL?
Data Protection Policy
Log Security
Where do you set DPPs?
On a Log Group
Log Security
What happens when a DPP finds something bad in a log?
Can redact it or send an audit message elsewhere