logo

Database

Aws Instance Logs Disabled

Description

Detects Amazon RDS database instances that have CloudWatch log exports disabled. Without CloudWatch log exports enabled, critical database logs are not captured for monitoring, auditing, and troubleshooting purposes, which reduces visibility into database activities and potential security incidents.

Weakness:

400 - Traceability Loss - AWS

Category: Functionality Abuse

Detection Strategy

    Examines each RDS database instance in the specified AWS region

    Checks if the 'EnabledCloudwatchLogsExports' property is empty or missing

    Reports a vulnerability if no log types are configured for export to CloudWatch Logs