Checks if Amazon OpenSearch Service domains have audit logging enabled. The rule is NON_COMPLIANT if an OpenSearch Service domain does not have audit logging enabled.

This config rule supports the following parameters:

  • cloudWatchLogsLogGroupArnList
    • Required: No
    • Type: CSV
    • Description:Comma-separated list of Amazon CloudWatch Logs log groups that should be configured for audit logs.

ConfigRule
AWS::Config::ConfigRule


Scope

ComplianceResourceTypes

Source *
CustomPolicyDetails
SourceDetails

CloudFormation Template

Share Template